{"id":"CVE-2026-27016","aliases":["GHSA-fqx6-693c-f55g"],"url":"https://o3.security/vulnerability/CVE-2026-27016","summary":"LibreNMS has Stored XSS in Custom OID - unit parameter missing strip_tags()","details":"LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype) are sanitized. The unsanitized value is stored in the database and rendered without HTML escaping. This issue is fixed in version 26.2.0.","published":"2026-02-20T01:34:11.241Z","modified":"2026-07-15T01:48:58.804039475Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"librenms/librenms","fixedVersion":"26.2.0"}],"fix":{"url":"https://github.com/librenms/librenms/commit/3bea263e02441690c01dea7fa3fe6ffec94af335","label":"librenms/librenms@3bea263"},"references":[{"type":"WEB","url":"https://github.com/librenms/librenms/releases/tag/26.2.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27016.json"},{"type":"ADVISORY","url":"https://github.com/librenms/librenms/security/advisories/GHSA-fqx6-693c-f55g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27016"},{"type":"FIX","url":"https://github.com/librenms/librenms/commit/3bea263e02441690c01dea7fa3fe6ffec94af335"},{"type":"FIX","url":"https://github.com/librenms/librenms/pull/19040"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:58.804039475Z"}}