CVE-2026-6204 Details
Description
LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the underlying web server.
A remote code execution vulnerability has been identified in LibreNMS versions prior to 26.3.0. This vulnerability allows authenticated administrators to execute arbitrary code on the server by manipulating the 'Binary Locations' configuration and using the Netcommand feature. Exploitation involves bypassing input validation to execute malicious scripts, potentially compromising the underlying web server.
Users are advised to update LibreNMS to version 26.3.0 or later. For versions prior to 26.3.0, consider loading binary paths from a configuration file instead of the WebUI, or enforce stricter validations to prevent the bypass that allows remote code execution.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/librenms/librenms/security/advisories/GHSA-pr3g-phhr-h8fh | PRJBLK | Third Party Advisory |
| https://projectblack.io/blog/librenms-authenticated-rce-and-xss/#binary-path-rce-poc | PRJBLK | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | PRJBLK |
Affected Products
| Product | Versions |
|---|---|
| librenms librenms | < 26.3.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | PRJBLK |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Initial Analysis | [email protected] |
| Apr 13, 2026 | New CVE Received | PRJBLK |