๐Ÿ” CVE Alert

CVE-2026-26988

UNKNOWN 0.0

LibreNMS: SQL Injection in ajax_table.php spreads through a covert data stream

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in the ajax_table.php endpoint. The application fails to properly sanitize or parameterize user input when processing IPv6 address searches. Specifically, the address parameter is split into an address and a prefix, and the prefix portion is directly concatenated into the SQL query string without validation. This allows an attacker to inject arbitrary SQL commands, potentially leading to unauthorized data access or database manipulation. This issue has been fixed in version 26.2.0.

CWE CWE-89
Vendor librenms
Product librenms
Published Feb 20, 2026
Last Updated Feb 20, 2026
Stay Ahead of the Next One

Get instant alerts for librenms librenms

Be the first to know when new unknown vulnerabilities affecting librenms librenms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

librenms / librenms
< 26.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/librenms/librenms/security/advisories/GHSA-h3rv-q4rq-pqcv github.com: https://github.com/librenms/librenms/pull/18777 github.com: https://github.com/librenms/librenms/commit/15429580baba03ed1dd377bada1bde4b7a1175a1