LibreNMS through 26.9.1.1 contains an authorization bypass vulnerability in includes/html/graphs/smokeping/auth.inc.php that checks the src probe device instead of the rendered target device. Restricted users permitted on a probe device can request smokeping_in or smokeping_out graphs with arbitrary device ids to view latency data and enumerate device names.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreNMS through 26.9.1.1 contains an authorization bypass vulnerability in includes/html/graphs/smokeping/auth.inc.php that checks the src probe device instead of the rendered target device. Restricted users permitted on a probe device can request smokeping_in or smokeping_out graphs with arbitrary device ids to view latency data and enumerate device names. | |
| Title | LibreNMS through 26.9.1.1 Authorization Bypass via Smokeping Graph auth.inc.php | |
| First Time appeared |
Librenms
Librenms librenms |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Librenms
Librenms librenms |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:27.963Z
Reserved: 2026-10-11T01:51:49.085Z
Link: CVE-2026-108715
No data.
Status : Received
Published: 2026-10-11T13:17:14.577
Modified: 2026-10-11T13:17:14.577
Link: CVE-2026-108715
No data.
OpenCVE Enrichment
Updated: 2026-10-11T13:30:19Z
Weaknesses