Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 07 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL type coercion by sending small integers like 0 through 9 to match token hashes, gaining access to API functionality including device credentials and administrative features that enable remote code execution through alert templates. | |
| Title | LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion | |
| First Time appeared |
Librenms
Librenms librenms |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Librenms
Librenms librenms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-07T12:53:47.884Z
Reserved: 2026-09-07T12:33:13.368Z
Link: CVE-2026-86426
No data.
Status : Received
Published: 2026-09-07T13:20:41.690
Modified: 2026-09-07T13:20:41.690
Link: CVE-2026-86426
No data.
OpenCVE Enrichment
Updated: 2026-09-07T16:30:06Z
-
CWE-287
Improper Authentication