๐Ÿ” CVE Alert

CVE-2026-86426

UNKNOWN 0.0

LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL type coercion by sending small integers like 0 through 9 to match token hashes, gaining access to API functionality including device credentials and administrative features that enable remote code execution through alert templates.

CWE CWE-287
Vendor librenms
Product librenms
Published Sep 7, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for librenms librenms

Be the first to know when new unknown vulnerabilities affecting librenms librenms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

librenms / librenms
0 < 26.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/librenms/librenms/security/advisories/GHSA-cvq8-gqfq-3mvg vulncheck.com: https://www.vulncheck.com/advisories/librenms-before-26.8.0-authentication-bypass-via-api-token-type-confusion

Credits

๐Ÿ” rbs-astsec