CVE-2026-26991 | LibreNMS up to 26.1.x HTTP POST Request /device-groups cross site scripting (GHSA-5pqf-54qp-32wx)
A vulnerability has been found in LibreNMS up to 26.1.x and classified as problematic. This affects an unknown part of the file /device-groups of the component HTTP POST Request Handler. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-26991. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.