{"id":"CVE-2026-84188","title":"LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php","summary":"LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrato…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"published":"2026-09-01","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:18:59.270","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84188","references":[{"url":"https://github.com/librenms/librenms/security/advisories/GHSA-7cj5-v4pp-v632","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/librenms-before-26.7.0-stored-xss-via-graph-descr-settings","label":"disclosure@vulncheck.com"},{"url":"https://github.com/librenms/librenms/security/advisories/GHSA-7cj5-v4pp-v632","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.0018,"epssPercentile":0.07822,"ingestedAt":"2026-09-08T21:11:12.288Z","slug":"CVE-2026-84188","body":"## Overview\n\nLibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type. The issue is fixed in version 26.7.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}