Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. librenms/librenms
  4. ›
  5. GHSA-jf24-8g2h-2wg7

GHSA-jf24-8g2h-2wg7: LibreNMS Vulnerable to Remote Code Execution via AboutController

August 18, 2026

A Remote Code Execution (RCE) vulnerability exists in LibreNMS 26.3.1 through the AboutController. An authenticated administrator can manipulate the snmpget configuration parameter to execute arbitrary system commands. When the /about endpoint is accessed, the application executes the configured binary path via shell_exec() without proper validation. This vulnerability leads to complete server compromise, allowing attackers to establish reverse shells, exfiltrate sensitive data, and maintain persistent access.

Severity: High (CVSS 7.2) Attack Vector: Network Privileges Required: High (Administrator) User Interaction: None Impact: Complete system compromise with web server privileges


CategoryLevelDescription
ConfidentialityHIGHRead config files, database credentials, SSH keys
IntegrityHIGHCreate webshells, backdoors, modify code
AvailabilityHIGHDisrupt services, delete data, stop monitoring
ScopeCHANGEDCompromise extends beyond application to system

References

  • github.com/advisories/GHSA-jf24-8g2h-2wg7
  • github.com/librenms/librenms/releases/tag/26.5.0
  • github.com/librenms/librenms/security/advisories/GHSA-jf24-8g2h-2wg7

Code Behaviors & Features

Detect and mitigate GHSA-jf24-8g2h-2wg7 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 26.5.0

Fixed versions

  • 26.5.0

Solution

Upgrade to version 26.5.0 or above.

Impact 7.2 HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Source file

packagist/librenms/librenms/GHSA-jf24-8g2h-2wg7.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 10 Sep 2026 00:18:42 +0000.