CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-2728

CVE-2026-2728: Authenticated Stored Cross-Site Scripting (XSS) in LibreNMS RANCID Configuration

Amit Schendel
Amit Schendel
Senior Security Researcher

May 18, 2026·6 min read·61 visits

Executive Summary (TL;DR)

An authenticated Stored XSS vulnerability in the LibreNMS `showconfig` page allows administrative users to inject malicious scripts via the RANCID repository URL setting. This script executes when other administrators view the device configuration page, potentially leading to session hijacking or privilege abuse.

LibreNMS versions prior to 26.3.0 contain an authenticated Stored Cross-Site Scripting (XSS) vulnerability within the RANCID integration settings. The flaw occurs during the generation of the RANCID configuration repository link on the `showconfig` page, where user-supplied input is improperly neutralized before being inserted into an HTML href attribute. An attacker with administrative privileges can execute arbitrary JavaScript in the browser context of other administrators who view the affected page.

Vulnerability Overview

LibreNMS is an open-source network monitoring system that provides extensive device management capabilities, including integration with external configuration backup tools like RANCID. The RANCID integration allows network administrators to view device configuration histories directly from the LibreNMS web interface. The system retrieves the RANCID repository URL from the global configuration and embeds it into the DOM to render a clickable link for users.

The vulnerability, identified as CVE-2026-2728, resides in the showconfig page component responsible for rendering this repository link. The application fails to strictly neutralize the user-supplied repository URL before concatenating it into the href attribute of an anchor tag. This deficiency introduces a Stored Cross-Site Scripting (XSS) condition, classified under CWE-79.

Because the vulnerable configuration setting is restricted to administrative users, the attack requires high privileges to execute. The primary attack vector involves an attacker compromising or misusing a lower-tier administrative account to plant a malicious payload. The payload triggers when a separate administrator accesses the device configuration view, executing the injected script within their authenticated session.

Root Cause Analysis

The root cause of CVE-2026-2728 lies in the implementation of the showconfig.inc.php script, specifically in how it constructs the HTML output for the Git repository link. The application retrieves the rancid_repo_url variable from the configuration store and applies the htmlspecialchars() function before concatenation. The intended security control is to escape special characters to prevent HTML injection.

Despite the use of htmlspecialchars(), the vulnerability persists due to the specific context of the string concatenation and attribute generation. The structure of the surrounding HTML output enables an attacker to bypass the intended sanitization. The attacker crafts a payload that successfully closes the href attribute and introduces new DOM elements and event handlers.

The application relies on implicit attribute bounding rather than strict URL validation or proper DOM creation libraries. The application does not verify that the configuration value is a valid, safe URL scheme (such as restricting it to http:// or https://). Consequently, the lack of robust input validation during the configuration save phase combined with contextual output rendering flaws creates the execution primitive.

Code Analysis

The vulnerability manifests in includes/html/pages/device/showconfig.inc.php. The application checks if the rancid_repo_url is set and proceeds to build an anchor link for users to browse the repository. The vulnerable code executes direct string concatenation inline with the HTML echo statement.

// Vulnerable Code Snippet
print_optionbar_start('', '');
echo is_null(LibrenmsConfig::get('rancid_repo_url')) ? 'Git repository non-browsable' : '<a href="' . htmlspecialchars(LibrenmsConfig::get('rancid_repo_url')) . '/?a=blob;hb=HEAD;p=' . basename((string) $rancid_path) . ';f=' . $rancid_file . '">Git repository</a>';
print_optionbar_end();

The attacker-controlled input is passed through htmlspecialchars(). However, the attacker supplies a payload explicitly designed to break out of the HTML attribute context: "><img/src/onerror=alert(1)><a x=". When this value is processed and concatenated into the href parameter, it manipulates the resulting DOM structure.

The patched versions introduce stricter input validation and employ proper URL encoding techniques for configuration variables intended for use as uniform resource locators. The fix ensures that characters required to break out of the attribute structure are neutralized entirely, preventing the injection of unauthorized tags such as the malicious <img> element used in the proof-of-concept.

Exploitation & Attack Methodology

Exploiting CVE-2026-2728 requires satisfying several specific preconditions. The attacker must authenticate with administrative privileges and ensure that RANCID integration is actively configured within LibreNMS. The integration requires the rancid_repo_type to be set to git-bare. Furthermore, the server must host a valid Git repository containing files at the configured path, as LibreNMS validates the repository's existence using git ls-tree before rendering the vulnerable link.

The attacker begins by navigating to the RANCID Integration panel located at Settings -> External. The attacker configures a valid local repository path, such as /opt/librenms/rancid/repo.git. The attacker then injects the XSS payload "><img/src/onerror=alert(1)><a x=" directly into the "RANCID Repository URL" field and saves the configuration.

The exploitation chain concludes when another user, typically a targeted administrator, navigates to the "Show Config" tab for any device associated with the modified RANCID configuration. The browser parses the manipulated HTML structure, attempts to load the invalid image source, and immediately executes the JavaScript defined in the onerror handler within the victim's session.

Impact Assessment

The successful exploitation of CVE-2026-2728 grants the attacker arbitrary JavaScript execution capabilities within the context of the victim's authenticated session. Because the payload triggers on an administrative interface, the victim is highly likely to possess elevated privileges. This execution primitive violates the integrity and confidentiality of the targeted user session.

An attacker can weaponize the JavaScript payload to perform unauthorized actions on behalf of the victim. These actions include modifying system configurations, adding backdoors, creating new administrative accounts, or harvesting sensitive data displayed within the application. The script can also interact with the LibreNMS API seamlessly by leveraging the victim's existing session tokens and cookies.

The vulnerability holds a CVSS v3.1 base score of 4.8. The score reflects the required high privileges (PR:H) and necessary user interaction (UI:R), which reduce the base exploitability. The EPSS score is 0.00004, indicating an extremely low probability of widespread exploitation in the wild, largely due to the restrictive authentication prerequisites.

Remediation and Mitigation

The primary remediation for CVE-2026-2728 is to upgrade LibreNMS to version 26.3.0 or a subsequent release. The maintainers introduced patches that implement rigorous sanitization for external configuration parameters before they are rendered in the HTML context. Administrators should apply the update during the next available maintenance window to eliminate the vulnerability.

Organizations that cannot immediately apply the patch can implement configuration-based mitigations. The most effective interim solution is to disable the RANCID integration completely if the functionality is not actively utilized for operational tasks. Disabling the integration prevents the application from executing the vulnerable code path that generates the repository link.

Security teams should actively audit the administrative user base and adhere to the principle of least privilege. Monitor system logs for unauthorized or suspicious modifications to the RANCID Integration settings. Implementing robust egress filtering and Content Security Policy (CSP) headers can further reduce the impact of successful XSS injections by preventing data exfiltration.

Official Patches

LibreNMSLibreNMS 26.3.0 Release Notes

Technical Appendix

CVSS Score
4.8/ 10
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS Probability
0.00%
Top 100% most exploited

Affected Systems

LibreNMS

Affected Versions Detail

Product
Affected Versions
Fixed Version
LibreNMS
LibreNMS
< 26.3.026.3.0
AttributeDetail
CWE IDCWE-79
Attack VectorNetwork
CVSS v3.1 Score4.8
EPSS Score0.00004
ImpactHigh (Session Hijacking / Privilege Abuse)
Exploit StatusProof of Concept Available
CISA KEVNot Listed

MITRE ATT&CK Mapping

T1189Drive-by Compromise
Initial Access
T1185Browser Session Hijacking
Collection
CWE-79
Cross-site Scripting

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Known Exploits & Detection

Project BlackTechnical analysis and Proof of Concept detailing the payload structure and execution requirements.

Vulnerability Timeline

Vulnerability disclosed and CVE-2026-2728 published.
2026-04-13
Project Black publishes technical analysis and PoC.
2026-04-13
LibreNMS releases version 26.3.0 containing the fix.
2026-04-13
CVE data last modified.
2026-04-22

References & Sources

  • [1]NVD Vulnerability Detail - CVE-2026-2728
  • [2]CVE.org Record - CVE-2026-2728
  • [3]Project Black Technical Blog
  • [4]LibreNMS GitHub Repository
  • [5]LibreNMS 26.3.0 Release Notes

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•10 minutes ago•CVE-2026-102821
6.5

CVE-2026-102821: Unbounded Memory Exhaustion via CHANNEL_OPEN Flood in russh

An uncontrolled resource consumption vulnerability in the russh library allows remote authenticated attackers to exhaust server memory (heap) by flooding channel open requests during a stalled key re-exchange (rekeying) process, causing a denial of service via Out-of-Memory (OOM) termination.

Alon Barad
Alon Barad
1 views•5 min read
•about 1 hour ago•CVE-2026-102820
6.2

CVE-2026-102820: Out-of-Bounds Read and Excessive Memory Allocation in russh pageant

A critical memory handling vulnerability exists in the pageant crate, a workspace component of the Rust-based russh SSH client library, during communication with the PuTTY Pageant SSH agent on Windows systems. Prior to version 0.2.3, the library's shared memory parsing logic blindly trusted a peer-controlled, 32-bit big-endian response length field. This allows local attackers running within the same user session to trigger out-of-bounds reads or execute an out-of-memory crash of the client application.

Amit Schendel
Amit Schendel
3 views•5 min read
•about 2 hours ago•CVE-2026-84428
7.5

CVE-2026-84428: Schema Validation Bypass in Fastify Header Normalization

A validation bypass vulnerability exists in Fastify web framework prior to version 5.12.2. The flaw stems from shallow normalization of header validation schemas, which fails to lowercase nested or conditional schema rules (like JSON Schema dependencies or dependentRequired) defined in mixed or canonical casing. Consequently, because Node.js normalizes incoming HTTP request headers to lowercase, the compiled validator fails to match these headers against the un-normalized mixed-case schema triggers, silently skipping conditional checks and allowing unauthenticated attackers to bypass authorization or security headers.

Amit Schendel
Amit Schendel
4 views•8 min read
•about 3 hours ago•CVE-2026-84469
7.5

CVE-2026-84469: Request Validation Bypass in Fastify via Loose Boolean Schema Evaluation

CVE-2026-84469 is a high-severity request validation bypass vulnerability in the Fastify Node.js web framework. In versions prior to 5.12.2, Fastify uses loose truthiness checks to decide whether to compile request schemas. When a component (such as the body) is explicitly configured with a boolean 'false' schema—which under JSON Schema Draft 7 acts as a 'deny-all' constraint—Fastify's internal logic evaluates this as a falsy value and skips compilation entirely. This allows unauthenticated remote attackers to send arbitrary payloads to these endpoints, bypassing validation checks and directly executing backend route handlers.

Alon Barad
Alon Barad
5 views•7 min read
•about 4 hours ago•CVE-2026-76169
7.5

CVE-2026-76169: Authentication Bypass and Encapsulation Violation via Malformed URL Routing Fallback in Fastify

An authentication bypass vulnerability in the Fastify web framework allows remote attackers to access private custom not-found handlers by submitting requests with malformed URLs. This bypasses the typical request lifecycle and its associated authorization hooks.

Amit Schendel
Amit Schendel
5 views•5 min read
•about 5 hours ago•CVE-2026-84504
8.1

CVE-2026-84504: Schema Validation Bypass via Async Validation Result Collision in Fastify

An API contract mismatch in the Fastify web framework allows remote attackers to bypass schema validation when asynchronous schema validators are used. When a route uses async validation, the validator resolves with the raw request body. If the body contains a root-level key named 'value', the validation runner interprets this as a synchronous wrapper envelope, extracting and promoting the unvalidated nested content to the root level of request.body.

Amit Schendel
Amit Schendel
5 views•6 min read