# LibreNMS Patches Multiple RCE and SSRF Flaws

Published: 2026-08-04 · Severity: medium · Sectors: infrastructure
Canonical: https://vorant.io/reports/07f177b3-ef25-5fd6-8b86-4733474a6ba7/librenms-patches-multiple-rce-and-ssrf-flaws

> LibreNMS versions before 26.5.0 contain multiple vulnerabilities enabling remote code execution, SSRF, and XSS.

ANSSI-CERT-FR published an advisory covering multiple vulnerabilities in LibreNMS, an open-source network monitoring platform, affecting all versions prior to 26.5.0. The flaws allow attackers to achieve remote code execution, perform server-side request forgery (SSRF), and inject indirect remote cross-site scripting (XSS) attacks. These issues were disclosed via seven separate GitHub security advisories on August 4, 2026, and tracked under CVE-2026-45694.

No evidence of active exploitation is mentioned in the advisory. Administrators running LibreNMS should apply the vendor's patches by upgrading to version 26.5.0 or later as referenced in the official security bulletins.

## Mentioned in this report

- Vulnerabilities: CVE-2026-45694

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0966

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/07f177b3-ef25-5fd6-8b86-4733474a6ba7/librenms-patches-multiple-rce-and-ssrf-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
