Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. librenms/librenms
  4. ›
  5. CVE-2026-55182

CVE-2026-55182: LibreNMS Vulnerable to Remote Code Execution by Signal Alert Transportation module

August 18, 2026

A vulnerability has been identified that allows an authenticated administrator to execute arbitrary code on the host server. By adding an alert transport entry, an attacker with administrative privileges can execute malicious commands.

References

  • github.com/advisories/GHSA-c9fv-cgmm-2wg7
  • github.com/librenms/librenms/releases/tag/26.5.0
  • github.com/librenms/librenms/security/advisories/GHSA-c9fv-cgmm-2wg7
  • nvd.nist.gov/vuln/detail/CVE-2026-55182

Code Behaviors & Features

Detect and mitigate CVE-2026-55182 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 21.6.0 before 26.5.0

Fixed versions

  • 26.5.0

Solution

Upgrade to version 26.5.0 or above.

Impact 7.2 HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')

Source file

packagist/librenms/librenms/CVE-2026-55182.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 06 Sep 2026 12:17:32 +0000.