Ghostwire

CVE-2026-2728: LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig...

LOW CVSS 2.5 EPSS 0.00%

Published: April 13, 2026 | Last Modified: April 14, 2026

Description

LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the page.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.00% (0th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (15 articles)

References