CVE-2020-15874

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.

  • Published Aug 26, 2026
  • CVSS 8.8 high
  • 1.1% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

CVE-2020-15874 at the National Vulnerability Database