GHSA-79q9-wc6p-cf92 · Severity: high · Ecosystem: composer — LibreNMS has a Time-Based Blind SQL Injection in address-search.inc.php
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Based Blind SQL Injection vulnerability in address-search.inc.php via the address parameter. When a crafted subnet prefix is supplied, the prefix value is concatenated directly into an SQL query without proper parameter binding, allowing an attacker to manipulate query logic and infer database information through time-based conditional responses. This vulnerability requires authentication and is exploitable by any authenticated user. This issue has been fixedd in version 26.2.0.
Conclusion & alert: CVE-2026-26990 is rated High Exploit Risk (85.5/100): CVSS High severity, with medium exploitation likelihood (EPSS 4.05%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +4.05% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.00% | 4.05% | +4.05% |
| 2 | 2026-02-20 | — | 0.00% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
GHSA-79q9-wc6p-cf92 · Severity: high · Ecosystem: composer — LibreNMS has a Time-Based Blind SQL Injection in address-search.inc.php
| URL | Tags |
|---|---|
| https://github.com/librenms/librenms/commit/15429580baba03ed1dd377bada1bde4b7a1175a1 | Patch |
| https://github.com/librenms/librenms/pull/18777 | Issue Tracking |
| https://github.com/librenms/librenms/security/advisories/GHSA-79q9-wc6p-cf92 | Exploit Third Party Advisory |