Impact
LibreNMS versions up to 26.9.1.1 contain an authorization bypass that occurs in the smokeping graph authentication script. The code validates the source probe device rather than the rendered target device, letting users who have permissions on one probe request graphs for any device ID. This allows restricted users to retrieve latency data and discover device names they should not see. The flaw yields unauthorized access to certain network visibility information and potential enumeration of the monitored network.
Affected Systems
All installations of LibreNMS running version 26.9.1.1 or earlier are vulnerable. Any environment where users are assigned probe permissions in a shared system, regardless of overall role, may be exposed. The vulnerability applies to the LibreNMS web interface and smokeping graph endpoints on those versions.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity, and its EPSS score is not available. It is not listed in the CISA KEV catalog, suggesting no documented exploitation yet. An attacker needs an authenticated session with probe access, but not necessarily administrator rights. The flaw can be leveraged by any user within the system who has probe permissions, allowing them to view latency graphs for arbitrary devices and infer device names, providing limited but valuable reconnaissance capabilities. The likelihood of exploitation is moderate, but the potential for information disclosure warrants prompt attention.
OpenCVE Enrichment