LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected… (CVE-2026-86426)
LibreNMS versions before 26.8.0 have an authentication bypass vulnerability in the REST API. This flaw allows unauthenticated attackers to access protected API endpoints by exploiting MySQL type coercion with numeric values instead of string tokens. Successful exploitation can expose device credentials and administrative features, potentially enabling remote code execution via alert templates.
AI Analysis
Technical Summary
CVE-2026-86426 describes an authentication bypass vulnerability in LibreNMS prior to version 26.8.0. The REST API improperly handles authentication tokens by allowing numeric values (0-9) to bypass token validation due to MySQL type coercion. This enables unauthenticated attackers to access protected API endpoints, including those that expose sensitive device credentials and administrative functions. The administrative features accessible through this bypass can be leveraged to execute remote code via alert templates, posing a critical security risk.
Potential Impact
The vulnerability allows unauthenticated attackers to bypass authentication controls in the LibreNMS REST API, leading to unauthorized access to sensitive device credentials and administrative functions. This can result in full system compromise through remote code execution, severely impacting confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
A fix is available in LibreNMS version 26.8.0. Users should upgrade to version 26.8.0 or later to remediate this vulnerability. No other mitigation guidance is provided in the available data.
LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected… (CVE-2026-86426)
Description
LibreNMS versions before 26.8.0 have an authentication bypass vulnerability in the REST API. This flaw allows unauthenticated attackers to access protected API endpoints by exploiting MySQL type coercion with numeric values instead of string tokens. Successful exploitation can expose device credentials and administrative features, potentially enabling remote code execution via alert templates.
CVSS v3.1
Score 9.8critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-86426 describes an authentication bypass vulnerability in LibreNMS prior to version 26.8.0. The REST API improperly handles authentication tokens by allowing numeric values (0-9) to bypass token validation due to MySQL type coercion. This enables unauthenticated attackers to access protected API endpoints, including those that expose sensitive device credentials and administrative functions. The administrative features accessible through this bypass can be leveraged to execute remote code via alert templates, posing a critical security risk.
Potential Impact
The vulnerability allows unauthenticated attackers to bypass authentication controls in the LibreNMS REST API, leading to unauthorized access to sensitive device credentials and administrative functions. This can result in full system compromise through remote code execution, severely impacting confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
A fix is available in LibreNMS version 26.8.0. Users should upgrade to version 26.8.0 or later to remediate this vulnerability. No other mitigation guidance is provided in the available data.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-84cr-xjpw-q9mc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-86426"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6aade4ea55bf5e2cf5ed9f0e
Added to database: 09/19/2026, 01:27:06 UTC
Last enriched: 09/19/2026, 01:34:26 UTC
Last updated: 09/19/2026, 02:01:10 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.