CVE-2026-26988 | LibreNMS up to 26.1.x Query String ajax_table.php sql injection (GHSA-h3rv-q4rq-pqcv)
A vulnerability classified as critical was found in LibreNMS up to 26.1.x. Affected is an unknown function of the file ajax_table.php of the component Query String Handler. Such manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-26988. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.