Description
LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host server.
Published: 2026-08-26
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

LibreNMS’s Virtualization Discovery module allows an authenticated administrator to perform command line injection, enabling arbitrary code execution on the host server. The vulnerability arises from insufficient input validation of commands processed by the module, making the system highly susceptible to exploitation. The impact is full compromise of the server, providing an attacker with the same privileges as the admin user.

Affected Systems

The affected product is LibreNMS from the vendor librenms. No specific version range is listed in the data, so any installation that includes the Virtualization Discovery module and grants authenticated admin users access is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity level. EPSS data is unavailable, so the current likelihood of exploitation is undetermined, but the vulnerability is listed as not in the CISA KEV catalog, suggesting no known active exploits yet. The attacker would need authenticated admin access; once logged in, the command line injection can be triggered through the module’s input fields. This yields remote code execution with no apparent restriction on the commands that can be run.

Generated by OpenCVE AI on August 26, 2026 at 03:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch that fixes the command‑line injection in the Virtualization Discovery module; see the official advisory for version details.
  • Restrict the pool of authenticated administrators to the minimum necessary; revoke or re‑assign any super‑user accounts that are not required for day‑to‑day operations.
  • If the module is not essential, disable or uninstall the Virtualization Discovery feature and audit LibreNMS logs for any unexpected command execution attempts; consider adding a web application firewall to filter injectable inputs.

Generated by OpenCVE AI on August 26, 2026 at 03:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Librenms
Librenms librenms
Vendors & Products Librenms
Librenms librenms

Wed, 26 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Description LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host server.
Title LibreNMS Virtualisation Discovery Module RCE
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Librenms Librenms
cve-icon MITRE

Status: PUBLISHED

Assigner: PRJBLK

Published:

Updated: 2026-08-26T02:11:01.673Z

Reserved: 2026-08-26T01:59:05.266Z

Link: CVE-2026-80214

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T03:30:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')