CVE-2026-108715
Received Received - Intake

Authorization Bypass in LibreNMS via Smokeping Graphs

Vulnerability report for CVE-2026-108715, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

LibreNMS through 26.9.1.1 contains an authorization bypass vulnerability in includes/html/graphs/smokeping/auth.inc.php that checks the src probe device instead of the rendered target device. Restricted users permitted on a probe device can request smokeping_in or smokeping_out graphs with arbitrary device ids to view latency data and enumerate device names.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
librenms librenms 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

LibreNMS through version 26.9.1.1 has an authorization bypass vulnerability in the Smokeping graph functionality. The issue occurs in includes/html/graphs/smokeping/auth.inc.php where the system checks authorization based on the source probe device instead of the target device being rendered. This allows restricted users with access to a probe device to request graphs for any device by manipulating device IDs, enabling them to view latency data and enumerate device names without proper authorization.

Detection Guidance

Check LibreNMS logs for unauthorized access attempts to smokeping graphs. Inspect auth.inc.php for incorrect authorization checks on probe devices instead of target devices. Review graph generation requests for manipulated device IDs.

Impact Analysis

An attacker with low privileges who has access to a probe device can bypass authorization checks and view smokeping graphs for any target device. This exposes sensitive latency data, packet loss metrics, and other telemetry information for restricted devices. Additionally, device names can be enumerated through graph titles, potentially revealing network infrastructure details.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive network monitoring data, potentially violating data protection requirements under GDPR and HIPAA. Exposure of device names and performance metrics may constitute a breach of confidentiality obligations, especially if the data relates to protected health information or personally identifiable network infrastructure details.

Mitigation Strategies

Upgrade LibreNMS to the latest version beyond 26.9.1.1. Temporarily restrict access to smokeping graph functionality for low-privilege users. Monitor network traffic for suspicious graph requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108715. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart