LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are affected by a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Rules workflow. An attacker with administrative privileges can inject malicious scripts that execute in the browser context of any user who accesses the Alert Rules page. This issue has been fixed in version 26.2.0.
References
| Link | Resource |
|---|---|
| https://github.com/librenms/librenms/commit/087608cf9f851189847cb8e8e5ad002e59170c58 | Patch |
| https://github.com/librenms/librenms/pull/19039 | Issue Tracking |
| https://github.com/librenms/librenms/releases/tag/26.2.0 | Product Release Notes |
| https://github.com/librenms/librenms/security/advisories/GHSA-6xmx-xr9p-58p7 | Exploit Third Party Advisory |
Configurations
History
20 Feb 2026, 16:25
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Librenms librenms
Librenms |
|
| CPE | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* | |
| References | () https://github.com/librenms/librenms/commit/087608cf9f851189847cb8e8e5ad002e59170c58 - Patch | |
| References | () https://github.com/librenms/librenms/pull/19039 - Issue Tracking | |
| References | () https://github.com/librenms/librenms/releases/tag/26.2.0 - Product, Release Notes | |
| References | () https://github.com/librenms/librenms/security/advisories/GHSA-6xmx-xr9p-58p7 - Exploit, Third Party Advisory |
20 Feb 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-20 02:16
Updated : 2026-02-20 16:25
NVD link : CVE-2026-26989
Mitre link : CVE-2026-26989
CVE.ORG link : CVE-2026-26989
JSON object : View
Products Affected
librenms
- librenms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
