Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snmpget configuration parameter is passed to shell_exec() without proper validation. An authenticated administrator can modify the snmpget configuration to point to a malicious executable file and trigger code execution by accessing the /about endpoint. | |
| Title | LibreNMS before 26.5.0 Remote Code Execution via AboutController | |
| First Time appeared |
Librenms
Librenms librenms |
|
| Weaknesses | CWE-77 | |
| CPEs | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Librenms
Librenms librenms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-01T12:12:49.860Z
Reserved: 2026-09-01T10:51:59.728Z
Link: CVE-2026-84190
No data.
Status : Received
Published: 2026-09-01T12:17:48.450
Modified: 2026-09-01T12:17:48.450
Link: CVE-2026-84190
No data.
OpenCVE Enrichment
No data.
-
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')