CVE-2026-27016

Source
https://cve.org/CVERecord?id=CVE-2026-27016
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27016.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-27016
Aliases
Published
2026-02-20T01:34:11.241Z
Modified
2026-03-03T02:56:17.173712Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
LibreNMS has Stored XSS in Custom OID - unit parameter missing strip_tags()
Details

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype) are sanitized. The unsanitized value is stored in the database and rendered without HTML escaping. This issue is fixed in version 26.2.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27016.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-116",
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/librenms/librenms

Affected ranges

Type
GIT
Repo
https://github.com/librenms/librenms
Events

Affected versions

24.*
24.10.0
24.10.1
24.11.0
24.12.0
25.*
25.1.0
25.10.0
25.11.0
25.12.0
25.2.0
25.3.0
25.4.0
25.5.0
25.6.0
25.7.0
25.8.0
25.9.0
26.*
26.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27016.json"