/Vulnerability Library

LibreNMS <= 26.7.0 - Unauthenticated API Access

CVE-2026-86426
Verified

Description

LibreNMS <= 26.8.0 contains an authentication bypass caused by MySQL type coercion in the REST API token validation, letting unauthenticated attackers access protected endpoints and execute remote code via alert templates.

Severity

Critical

CVSS Score

9.2

Affected Product

librenms

Published Date

September 9, 2026

Template Author

0x_akoko

CVE-2026-86426.yaml
9.2Score

CVSS Metrics

CWE ID:
cwe-287

References

https://github.com/librenms/librenms/security/advisories/GHSA-cvq8-gqfq-3mvg

Remediation Steps

Update to version 26.8.0 or later.