CVE-2026-27016 is a medium-severity (CVSS 5.4) Cross-site Scripting (XSS) vulnerability in librenms/librenms. A fix is available for librenms/librenms — see the affected versions and patch details below.
LibreNMS has Stored XSS in Custom OID - unit parameter missing strip_tags()
Exploitation Status
No confirmed exploitation observed yet
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-27016.
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
How urgent is this, really
CVE-2026-27016 plotted by exploitation likelihood (EPSS) against impact (CVSS). The shaded corner — EPSS 50%+ and CVSS 7.0+ — is where this CVE doesn't sit, though severity or exploitability alone can still warrant action.
Where this sits among everything scored
Of 378,156 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Real counts from FIRST.org, not a sample — log-scaled since the landscape is heavily right-skewed.
Real-World Exposure
librenms/librenmsReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.
Description
Summary
The unit parameter in Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype) are sanitized. The unsanitized value is stored in the database and rendered without HTML escaping, allowing Stored XSS.
Details
Vulnerable Input Processing (includes/html/forms/customoid.inc.php lines 18-21):
$name = strip_tags((string) $_POST['name']); // line 18 - SANITIZED
$oid = strip_tags((string) $_POST['oid']); // line 19 - SANITIZED
$datatype = strip_tags((string) $_POST['datatype']); // line 20 - SANITIZED
$unit = $_POST['unit']; // line 21 - NOT SANITIZED!
Vulnerable Output (graphs/customoid.inc.php lines 13-20):
$customoid_unit = $customoid['customoid_unit']; // Retrieved from DB
$customoid_current = \LibreNMS\Util\Number::formatSi(...) . $customoid_unit;
echo "...$customoid_current..."; // ECHOED WITHOUT ESCAPING!
PoC
#!/usr/bin/env python3
"""
XSS test for LibreNMS Custom OID - unit parameter
"""
import html as html_module
import re
def strip_tags(value):
return re.sub(r'<[^>]*?>', '', str(value))
# Simulate form processing (customoid.inc.php lines 18-21)
test_inputs = {
'name': '<script>alert(1)</script>Test OID',
'oid': '1.3.6.1.4.1.2021.10.1.3.1',
'datatype': 'GAUGE',
'unit': '<script>alert("XSS")</script>',
}
name = strip_tags(test_inputs['name']) # Sanitized
oid = strip_tags(test_inputs['oid']) # Sanitized
datatype = strip_tags(test_inputs['datatype']) # Sanitized
unit = test_inputs['unit'] # NOT SANITIZED!
print("Input Processing Analysis:")
print(f" name (strip_tags): {name}")
print(f" oid (strip_tags): {oid}")
print(f" datatype (strip_tags): {datatype}")
print(f" unit (NO strip_tags): {unit}")
print()
print("*** VULNERABILITY: 'unit' parameter has NO strip_tags()! ***")
# Test XSS payloads
payloads = [
'<script>alert("XSS")</script>',
'<img src=x onerror=alert(1)>',
'<svg onload=alert(1)>',
]
print("\nXSS Payload Tests:")
for payload in payloads:
escaped = html_module.escape(payload)
has_xss = '<script>' in payload or 'onerror=' in payload.lower()
print(f" Payload: {payload}")
print(f" Raw (vulnerable): Contains executable code: {has_xss}")
print(f" Escaped (safe): {escaped}")
Expected Output
Input Processing Analysis:
name (strip_tags): alert(1)Test OID
oid (strip_tags): 1.3.6.1.4.1.2021.10.1.3.1
datatype (strip_tags): GAUGE
unit (NO strip_tags): <script>alert("XSS")</script>
*** VULNERABILITY: 'unit' parameter has NO strip_tags()! ***
Impact
- Attack Vector: User with device edit permissions sets malicious Unit value
- Exploitation: XSS payload stored in database, executes for all users viewing device graphs
- Consequences:
- Session hijacking via cookie theft
- Admin account takeover
- Malicious actions on behalf of victims
- Persistent attack affecting all users
- Affected Users: All LibreNMS installations with Custom OID feature
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐘Packagist | librenms/librenms | ≥ 24.10.0&&< 26.2.0 | 26.2.0composer require librenms/librenms:^26.2.0 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for librenms/librenms, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update librenms/librenms to 26.2.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-27016 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like CVE-2026-27016 can be triaged on real exposure rather than presence alone.
Tailored to CVE-2026-27016. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is CVE-2026-27016 in your dependencies?
O3 Security finds CVE-2026-27016 across Packagist dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.