# CERT-FR flags multiple LibreNMS vulnerabilities

Published: 2026-09-24 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/ee41943e-2c06-5eac-8853-7d7a18284b6c/cert-fr-flags-multiple-librenms-vulnerabilities

> CERT-FR warns of multiple vulnerabilities in LibreNMS before 26.9.0 enabling privilege escalation, XSS, SQL injection and data exposure.

CERT-FR issued an advisory covering multiple vulnerabilities in LibreNMS, an open-source network monitoring platform, affecting all versions prior to 26.9.0. The flaws collectively allow an attacker to achieve privilege escalation, breach data confidentiality and integrity, bypass security policies, and perform indirect remote code injection via cross-site scripting (XSS) and SQL injection (SQLi).

The advisory references five separate GitHub Security Advisories published by LibreNMS on 23 September 2026 (GHSA-2pw7-8mmj-gcw5, GHSA-9qcg-rgg9-mpjg, GHSA-cjqw-76mh-jmpv, GHSA-ffjc-4fr5-47c6, GHSA-j3qf-h24w-9f42), though no CVE identifiers or technical exploitation details are provided in the bulletin itself. No in-the-wild exploitation is mentioned.

Defenders running LibreNMS should upgrade to version 26.9.0 or later as soon as possible and consult the linked GitHub advisories for per-vulnerability technical details and patch guidance. Given LibreNMS's role as a network monitoring tool with broad visibility and often elevated access into infrastructure, organizations should prioritize patching and review authentication logs and admin-panel access for signs of privilege escalation attempts.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1222

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ee41943e-2c06-5eac-8853-7d7a18284b6c/cert-fr-flags-multiple-librenms-vulnerabilities.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
