Security Advisory

CVE-2026-30480

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-14 00:00:00
Last updated 2026-04-16 12:06:38
Assigner mitre
State PUBLISHED

Description

A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parameter.