{"id":"CVE-2026-84194","summary":"LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostname","details":"LibreNMS versions \u003e= 23.10.0 and \u003c 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in libvirt discovery. When libvirt support is enabled (enable_libvirt=true), the device hostname ($this-\u003egetDevice()-\u003ehostname) is concatenated into shell commands (ssh, virsh list/dumpxml/domstate) in VminfoLibvirt.php and passed to exec() without escapeshellarg() or argument separation. An authenticated admin can set a crafted device hostname to inject arbitrary OS commands, leading to remote code execution in the discovery worker context.","aliases":["GHSA-wff2-9gjr-95f3"],"modified":"2026-09-03T03:30:46.798943155Z","published":"2026-09-01T11:33:57.794Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84194.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84194.json"},{"type":"ADVISORY","url":"https://github.com/librenms/librenms/security/advisories/GHSA-wff2-9gjr-95f3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84194"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/librenms-23.10.0-before-26.4.0-os-command-injection-via-hostname"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/librenms/librenms","events":[{"introduced":"c22b74d46b307979a5b6a28b1a3a54e68b3152c4"},{"fixed":"5e70937c141d494b54215c973a62ec0fd9e3543a"}],"database_specific":{"extracted_events":[{"introduced":"23.10.0"},{"fixed":"26.4.0"}],"source":"AFFECTED_FIELD"}}],"versions":["26.3.1","26.3.0","26.2.0","26.1.0","25.12.0","25.11.0","25.10.0","25.9.0","25.8.0","25.7.0","25.6.0","25.5.0","25.4.0","25.3.0","25.2.0","25.1.0","24.12.0","24.11.0","24.10.1","24.10.0","24.9.1","24.9.0","24.8.0","24.7.0","24.6.0","24.5.0","24.4.1","24.4.0","24.3.0","24.2.0","24.1.0","23.11.0","23.10.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84194.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"}]}