CVE-2020-15878

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the address parameter in the /ajax_table.php API endpoint.

  • Published Aug 26, 2026
  • CVSS 8.8 high
  • 0.5% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

CVE-2020-15878 at the National Vulnerability Database