{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T19:04:59.141","vulnerabilities":[{"cve":{"id":"CVE-2026-27016","sourceIdentifier":"security-advisories@github.com","published":"2026-02-20T02:16:55.140","lastModified":"2026-06-17T10:26:32.463","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype) are sanitized. The unsanitized value is stored in the database and rendered without HTML escaping. This issue is fixed in version 26.2.0."},{"lang":"es","value":"LibreNMS es una herramienta de monitorización de red basada en PHP/MySQL/SNMP con auto-descubrimiento. Las versiones 24.10.0 hasta la 26.1.1 son vulnerables a XSS almacenado a través del parámetro 'unit' en Custom OID. La funcionalidad Custom OID no realiza una sanitización en strip_tags() mientras que otros campos (name, oid, datatype) están sanitizados. El valor no sanitizado se almacena en la base de datos y se renderiza sin escape HTML. Este problema está solucionado en la versión 26.2.0."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"librenms","product":"librenms","versions":[{"version":">= 24.10.0, < 26.2.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-20T15:26:32.832016Z","id":"CVE-2026-27016","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"},{"lang":"en","value":"CWE-116"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*","versionStartIncluding":"24.10.0","versionEndExcluding":"26.2.0","matchCriteriaId":"5DF70D72-DD59-426A-8938-18E877C05530"}]}]}],"references":[{"url":"https://github.com/librenms/librenms/commit/3bea263e02441690c01dea7fa3fe6ffec94af335","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/librenms/librenms/pull/19040","source":"security-advisories@github.com","tags":["Issue Tracking"]},{"url":"https://github.com/librenms/librenms/releases/tag/26.2.0","source":"security-advisories@github.com","tags":["Product","Release Notes"]},{"url":"https://github.com/librenms/librenms/security/advisories/GHSA-fqx6-693c-f55g","source":"security-advisories@github.com","tags":["Third Party Advisory"]}]}}]}