CVE-2026-86426
LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL type coercion by sending small integers like 0 through 9 to match token hashes, gaining access to API functionality including device credentials and administrative features that enable remote code execution through alert templates.
| CWE | CWE-287 |
| Vendor | librenms |
| Product | librenms |
| Published | Sep 7, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for librenms librenms
Be the first to know when new unknown vulnerabilities affecting librenms librenms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
librenms / librenms
0 < 26.8.0
References
Credits
๐ rbs-astsec