Description
LibreNMS through 26.9.1.1 contains an authorization bypass vulnerability in includes/html/graphs/smokeping/auth.inc.php that checks the src probe device instead of the rendered target device. Restricted users permitted on a probe device can request smokeping_in or smokeping_out graphs with arbitrary device ids to view latency data and enumerate device names.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Authorization Bypass
Action: Immediate Patch
AI Analysis

Impact

LibreNMS versions up to 26.9.1.1 contain an authorization bypass that occurs in the smokeping graph authentication script. The code validates the source probe device rather than the rendered target device, letting users who have permissions on one probe request graphs for any device ID. This allows restricted users to retrieve latency data and discover device names they should not see. The flaw yields unauthorized access to certain network visibility information and potential enumeration of the monitored network.

Affected Systems

All installations of LibreNMS running version 26.9.1.1 or earlier are vulnerable. Any environment where users are assigned probe permissions in a shared system, regardless of overall role, may be exposed. The vulnerability applies to the LibreNMS web interface and smokeping graph endpoints on those versions.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.3, indicating moderate severity, and its EPSS score is not available. It is not listed in the CISA KEV catalog, suggesting no documented exploitation yet. An attacker needs an authenticated session with probe access, but not necessarily administrator rights. The flaw can be leveraged by any user within the system who has probe permissions, allowing them to view latency graphs for arbitrary devices and infer device names, providing limited but valuable reconnaissance capabilities. The likelihood of exploitation is moderate, but the potential for information disclosure warrants prompt attention.

Generated by OpenCVE AI on October 11, 2026 at 13:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official LibreNMS update to version 26.9.1.2 or later, which corrects the authentication logic.
  • If immediate patching is not possible, revoke probe device permissions from users who should not have visibility into other devices and reassign probe management to a higher‑privilege role.
  • Disable or restrict access to smokeping graph endpoints for users without full authorization, ensuring that the auth.inc.php script validates the target device rather than the source probe.

Generated by OpenCVE AI on October 11, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description LibreNMS through 26.9.1.1 contains an authorization bypass vulnerability in includes/html/graphs/smokeping/auth.inc.php that checks the src probe device instead of the rendered target device. Restricted users permitted on a probe device can request smokeping_in or smokeping_out graphs with arbitrary device ids to view latency data and enumerate device names.
Title LibreNMS through 26.9.1.1 Authorization Bypass via Smokeping Graph auth.inc.php
First Time appeared Librenms
Librenms librenms
Weaknesses CWE-639
CPEs cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*
Vendors & Products Librenms
Librenms librenms
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Librenms Librenms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:27.963Z

Reserved: 2026-10-11T01:51:49.085Z

Link: CVE-2026-108715

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:14.577

Modified: 2026-10-11T13:17:14.577

Link: CVE-2026-108715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:30:19Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key