Description
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.
Published: 2026-08-26
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated attacker who only requires normal user privileges in LibreNMS 1.65 can run arbitrary shell commands by exploiting a command injection flaw in the /graph.php API endpoint. This flaw allows the attacker to gain full system compromise, enabling data exfiltration, tampering, or further lateral movement by executing shell commands with the privileges of the web server process.

Affected Systems

The vulnerability affects LibreNMS 1.65. The CVE data does not list other versions as affected; no other vendors or products are identified.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, but the lack of a public exploit list does not reduce its potential impact because it requires only normal authentication and would allow arbitrary code execution over the network. The attack vector is remote, relying on authenticated access, and the vulnerability would be straightforward to exploit for anyone who can log in.

Generated by OpenCVE AI on August 26, 2026 at 19:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update LibreNMS to version 1.65.1 or later, which contains the command injection fix.
  • If a newer version cannot be applied immediately, consider disabling the /graph.php endpoint or restricting it to trusted IP addresses via firewall or web server configuration.
  • Reduce the privileges of the web server user or harden the process isolation for the LibreNMS application to limit the consequences of an execution if the endpoint remains exposed.

Generated by OpenCVE AI on August 26, 2026 at 19:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Librenms
Librenms librenms
Vendors & Products Librenms
Librenms librenms

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Remote Authenticated Command Injection via /graph.php in LibreNMS 1.65
Weaknesses CWE-78

Wed, 26 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.
References

Subscriptions

Librenms Librenms
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-26T16:48:12.099Z

Reserved: 2020-07-21T00:00:00.000Z

Link: CVE-2020-15874

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T17:16:44.097

Modified: 2026-08-26T17:16:44.097

Link: CVE-2020-15874

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:45:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')