---
id: CVE-2026-80214
title: >-
  LibreNMS’s Virtualization Discovery module is vulnerable to command line
  injection
summary: >-
  LibreNMS’s Virtualization Discovery module is vulnerable to command line
  injection. An authenticated admin user can execute arbitrary code on the host
  server.
severity: none
cwe:
  - CWE-78
published: '2026-08-26'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:52:04.827'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80214'
references:
  - url: >-
      https://github.com/librenms/librenms/security/advisories/GHSA-7hmq-j399-mqwf
    label: ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a
  - url: >-
      https://projectblack.io/blog/librenms-authenticated-rce-26-5-0/#rce-by-command-line-injection-2641
    label: ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a
  - url: >-
      https://github.com/librenms/librenms/security/advisories/GHSA-7hmq-j399-mqwf
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00539
epssPercentile: 0.42904
ingestedAt: '2026-09-09T16:14:05.515Z'
---

## Overview

LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
