{"id":"CVE-2026-2728","aliases":["GHSA-5gm9-622f-qcg5"],"url":"https://o3.security/vulnerability/CVE-2026-2728","summary":"LibreNMS: Cross-Site Scripting in ShowConfigController","details":"LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the page.","published":"2026-04-13T10:39:54.757Z","modified":"2026-08-12T03:51:13.429173318Z","cvss":null,"epss":{"score":0.00225,"percentile":0.1334,"asOf":"2026-08-14"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"librenms/librenms","fixedVersion":"26.3.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2728.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2728"},{"type":"EVIDENCE","url":"https://projectblack.io/blog/librenms-authenticated-rce-and-xss/#xss-on-showconfig-page-2630"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.429173318Z"}}