Untriaged
Permalink
CVE-2026-86426
9.2 CRITICAL
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): Present (P)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): Present (P)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion
LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL type coercion by sending small integers like 0 through 9 to match token hashes, gaining access to API functionality including device credentials and administrative features that enable remote code execution through alert templates.
References
-
GitHub Security Advisory (GHSA-cvq8-gqfq-3mvg) vendor-advisory
Affected products
librenms
- ==26.8.0
- <26.8.0
Matching in nixpkgs
pkgs.librenms
Auto-discovering PHP/MySQL/SNMP based network monitoring
pkgs.python313Packages.aiolibrenms
Asynchronous library to fetch data from a LibreNMS instance
-
nixos-unstable -
- nixos-unstable-small 0.0.3
pkgs.python314Packages.aiolibrenms
Asynchronous library to fetch data from a LibreNMS instance
-
nixos-unstable -
- nixos-unstable-small 0.0.3
Package maintainers
-
@johannwagner Johann Wagner <nix@wagner.digital>
-
@NetaliDev Jennifer Graul <me@netali.de>
-
@JamieMagee Jamie Magee <jamie.magee@gmail.com>