peter bassill · operator
$ cve CVE-2026-86426 JSON

CVE-2026-86426

9.8
CRITICAL · CVSS 3.1 · EPSS 3.9% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL type coercion by sending small integers like 0 through 9 to match token hashes, gaining access to API functionality including device credentials and administrative features that enable remote code execution through alert templates.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.87% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2026-09-07
Last modified2026-09-18

Affected (1)

VendorProduct
librenmslibrenms

References

→ the Explorer  ·  watch your stack  ·  NVD