CVE-2026-45694 with a CVSS score of 5.4 is a vulnerability affecting librenms versions <= 26.4.0 in LibreNMS that allows reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignment, affecting all versions prior to the fixed version 26.5.0. The flaw type is CWE-79 and can be exploited through a crafted link by an authenticated session, allowing an attacker to execute arbitrary script. This vulnerability has a medium severity impact on business as it allows attackers to inject malicious code into user's browser.
We recommend you to update LibreNMS to version 26.5.0.[/subscribe_to_unlock_form]
CVE-2026-45694 with a CVSS score of 5.4 is a vulnerability affecting librenms versions <= 26.4.0 in LibreNMS that allows reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignment, affecting all versions prior to the fixed version 26.5.0. The flaw type is CWE-79 and can be exploited through a crafted link by an authenticated session, allowing an attacker to execute arbitrary script. This vulnerability has a medium severity impact on business as it allows attackers to inject malicious code into user's browser.
We recommend you to update LibreNMS to version 26.5.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]