S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 9, 2026

CVE-2026-86426 Scanner

CVE-2026-86426 Scanner - Unauthenticated API Access vulnerability in LibreNMS

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
6.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-86426
9.2
CVSScritical
Exploitable remotely over the internet · no authentication required.

LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL type coercion by sending small integers like 0 through 9 to match token hashes, gaining access to API functionality including device credentials and administrative features that enable remote code execution through alert templates.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
librenmsby librenms
AFFECTED< 26.8.0SAFE ✓≥ 26.8.0
Updated Sep 9, 2026View on NVD →
Detail

LibreNMS is an open-source network monitoring system used by organizations around the world to manage and monitor network devices. It provides comprehensive monitoring capabilities and is typically utilized by network administrators to ensure the health and performance of networks. LibreNMS integrates with a variety of devices and platforms, making it a versatile choice for monitoring. By using LibreNMS, users can receive alerts on network issues, monitor bandwidth usage, and track device health. It is a critical tool for IT departments seeking to maintain network reliability. LibreNMS has a wide user base, ranging from small businesses to large enterprises.

The vulnerability found in LibreNMS involves unauthenticated access to its API, which can occur due to a flaw in token validation. This critical issue allows attackers to bypass authentication mechanisms and gain access to restricted endpoints without proper credentials. The security weakness arises from MySQL type coercion exploited during REST API token validation processes. Exploiting this vulnerability could allow malicious users to execute remote code and compromise the network. Consequently, the vulnerability represents a significant security risk to organizations using vulnerable versions of LibreNMS. Understanding and addressing this gap is crucial for maintaining the integrity of network monitoring operations.

The unauthenticated API access vulnerability in LibreNMS is related to vulnerable endpoints in its REST API. The misuse arises from inadequate handling of API tokens, where the system fails to enforce strict authentication controls. Attackers can leverage this vulnerability by sending specially crafted requests to the API to execute undesirable actions. With type coercion in MySQL, the validation process can incorrectly authenticate malicious input as valid tokens. The endpoints most susceptible to this manipulation include those handling sensitive configuration and alert templates. Hence, the vulnerability's exploitation could lead to severe network and data exposure risks.

If the vulnerability is exploited, it can lead to a full system compromise. Malicious actors could execute arbitrary code, effectively gaining unauthorized control over the monitored network. This access can result in the theft or manipulation of sensitive network data, disruption of monitoring processes, and degradation of service reliability. Moreover, attackers could potentially deploy malware or launch further attacks on interconnected systems. The impact on network security and operations could be catastrophic, resulting in significant data loss and reputational damage for affected organizations.

REFERENCES

Solution Advice
  • Upgrade to LibreNMS version 26.8.0 or later to patch this vulnerability.
  • Implement strict access control measures for API endpoints.
  • Regularly review security advisories for any product you use and apply updates promptly.
  • Employ network segmentation to limit the exposure of vulnerable systems.
  • Use additional authentication layers for accessing critical monitoring components.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.