216.73.217.22

CVE-2026-2728

· Published 13/04/2026 11:16 · Modified 13/04/2026 15:01

Labels: CVE-2026-2728 2026-04-13CVE-2026-2728CWE-79ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a

Essential information

Published
13/04/2026 11:16
Modified
13/04/2026 15:01
Author
Creator
CVSS
4.6 MEDIUM (v3) 4.6 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the page.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a
NVD
View on NVD

Affected products (CPE)

ProductCPE
librenms / librenms cpe:2.3:a:librenms:librenms:<26.3.0:*:*:*:*:*:*:*

References