This release includes 5 security fixes for security teams reviewing exposed deployments.
Topics
+1 more
Affected surfaces
ReleasePort's take
Moderate signalThe release addresses critical security flaws in storage tables and API endpoints while adding new configuration options and UI fields.
Why it matters: Fixes XSS (severity 90) and CSRF (severity 85) vulnerabilities that could compromise web UI and API access; deploy to protect data integrity.
Summary
AI summaryBroad release touches https://github.com/murrant, https://github.com/laf, Webui, and Bug.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Update storage table to remove XSS vulnerabilities. Update storage table to remove XSS vulnerabilities. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Security | High |
Add CSRF check into ajax_form.php to prevent cross‑site request forgery. Add CSRF check into ajax_form.php to prevent cross‑site request forgery. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Security | High |
Implement and improve permission checks across APIs and UI components. Implement and improve permission checks across APIs and UI components. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Feature | Medium |
Add SnmpEngineID field to Core device discovery and edit pages. Add SnmpEngineID field to Core device discovery and edit pages. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Feature | Medium |
Introduce graylog.match-any-address configuration option for log routing. Introduce graylog.match-any-address configuration option for log routing. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Feature | Medium |
Add wireless sensors endpoint to the API. Add wireless sensors endpoint to the API. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Dependency | Medium |
Bump esbuild, vite and laravel-vite-plugin to latest versions. Bump esbuild, vite and laravel-vite-plugin to latest versions. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Dependency | Medium |
Raise minimum required RRDtool version to 1.5.5. Raise minimum required RRDtool version to 1.5.5. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Bugfix | Medium |
Fix RRD error handling to prevent crashes during data retrieval. Fix RRD error handling to prevent crashes during data retrieval. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Bugfix | Medium |
Change "vsz" column data type to BIGINT to accommodate larger values. Change "vsz" column data type to BIGINT to accommodate larger values. Source: llm_adapter@2026-06-15 Confidence: low |
— |
| Bugfix | Low |
Change "vsz" column type to BIGINT in the database schema. Change "vsz" column type to BIGINT in the database schema. Source: granite4.1:30b@2026-06-15-audit Confidence: low |
— |
Full changelog
26.6.0
(2026-06-15)
A big thank you to the following 32 contributors this last month:
- murrant (43)
- laf (28)
- dependabot (8)
- maggo1404 (3)
- tristanbob (3)
- Yoyasp (2)
- knpo (2)
- sergio-scl (2)
- craig-nokia (2)
- peelman (2)
- 49phil (2)
- takyanagida (1)
- Taarek (1)
- loopodoopo (1)
- danpal-dev (1)
- lirone (1)
- thundersin (1)
- WizballESY (1)
- robje (1)
- InsaneSplash (1)
- eskyuu (1)
- danjul89 (1)
- Npeca75 (1)
- moyito2604 (1)
- eduardomozart (1)
- isolson (1)
- anthonyp-cns (1)
- mpikzink (1)
- redundantredundancy (1)
- Jannos-443 (1)
- CCAkoutsio (1)
- LongHopeFreedom (1)
Thanks to maintainers and others that helped with pull requests this month:
- laf (67)
- murrant (32)
- copilot-pull-request-reviewer (3)
- Jellyfrog (1)
Feature
Security
- Update storage table to remove xss (#19896) - laf
- Added validation for ajax/select/port filter (#19877) - laf
- Check user has permission to access port for search_by_mac api function (#19876) - laf
- Stop leaking data when host add fails via api (#19870) - laf
- Stop widgets being moved that don't belong to that dashboard (#19868) - laf
- Fix some possible xss in various tables (#19867) - laf
- Validate wireless sensor updates against static list (#19863) - laf
- Add device permission check to add_eventlog api call (#19862) - laf
- Added a csrf check into ajax_form.php (#19859) - laf
- First round of updates to improve security (#19856) - laf
- Permissions implementations and improvements (#19643) - murrant
Device
- IOS-XR ignore optical and macsec if types (#19889) - knpo
- Add Versa Networks SD-WAN support (#19849) - loopodoopo
- Adding FMMC ports to iqnos dBm sensors (#19806) - thundersin
- Deltaups voltage divisor for Mini-SNMP firmware (#19797) - sergio-scl
- Add Albentia WiMAX BS support (#19796) - sergio-scl
- Add Moxa NP6150 sysObjectID (#19786) - WizballESY
- Updated OcNos transceiver to port mapping (#19783) - laf
- Add basic Nokia Wavence microwave support (#19750) - craig-nokia
- Add initial support for Genie ATM (#19739) - robje
- Set max oid 5 for exeltech-xfersw (#19722) - murrant
- Version-dependent divisor for SmartpackS rectifiersCurrent (#19718) - peelman
- Add ENVIROMUX 2D/5D/16D support and enrich E-MICRO-TRH(P) variant (#19717) - peelman
- Support RutOS 7.x table-based MIB (#19689) - danjul89
- Add GE Pulsar power system alarm sensors (#19681) - craig-nokia
- Liebert IntelliSlot Web/485 support (#19654) - moyito2604
- Add RoomAlert MAX support (#19435) - redundantredundancy
- Fix Conteg PDU divisor for power sensors (#19384) - CCAkoutsio
Webui
- Ports page better indicator colors (#19884) - murrant
- Fix Metro Ethernet table (#19854) - laf
- Fix graph time presets for week and month units (1w/2w/1mo/2mo) (#19835) - tristanbob
- Fix the device Access Points page using light coloured background (#19809) - laf
- Device overview graphs fill better (#19807) - murrant
- Update label for default group when using Socialite (#19791) - laf
- Fix alert detail sensor graph (#19781) - murrant
- Modals now appear lower than the navbar and reduced the gap below the navbar (#19777) - laf
- Increase device and port popup show delay (#19770) - murrant
- Add index to device display field (#19768) - murrant
- Filter bar widget search button shortcut (#19763) - murrant
- Port state filter refinement (#19762) - murrant
- Devices page handle legacy url filters (#19757) - murrant
- Filter handle empty and not empty better (#19756) - murrant
- Fix alert history graph when empty (#19751) - murrant
- Device Overview page UI updates (#19731) - laf
- Devices filter (#19725) - murrant
- Fix device inventory port link escape (#19723) - murrant
- Re-order port filters (#19719) - murrant
- Fix access permissions on port group list and page (#19714) - eskyuu
- Added port security filter and csv export (#19692) - laf
- Add graylog.match-any-address configuration option (#19445) - anthonyp-cns
Alerting
Api
- Add invert_map to add_edit_rule (#19890) - Yoyasp
- Add statistics to get_port_info (#19824) - knpo
- Add wireless sensors endpoint (#19461) - isolson
Discovery
Polling
Authentication
- Radius include message authenticator (#19715) - InsaneSplash
Bug
- RRD tune error handling (#19873) - murrant
- Fix issue with assigning some config types (#19869) - laf
- Filterable, bail on non-array (#19853) - murrant
- Decode legacy location names (#19852) - murrant
- Change "vsz" column to BigInt (#19851) - Taarek
- Rrd fix getRrdFiles (#19843) - murrant
- Fix rrdcached directory replacement (#19842) - murrant
- Directory cannot be a binary (#19839) - murrant
- Walk volume status table in storage discovery (#19826) - lirone
- Repair Show Previous on multi-interface bits graphs (#19821) - tristanbob
- Remove redundant ob_end_clean() after ob_get_clean() (#19811) - tristanbob
- Unifi avoid crash from bad response (#19766) - murrant
- Fix Janitza device detection (#19765) - murrant
- Update links to device groups and types (#19748) - laf
- Fix device:add display name flag (#19744) - murrant
- Fix duplicate eventlog for device attribute changes in some cases (#19740) - murrant
- Fix for orphaned alerts when device_id =< 0 (#19709) - laf
- Decode non-ASCII printer supplies descriptions (UTF-8 CJK support) (#19379) - LongHopeFreedom
Refactor
Cleanup
- Removed unused alert function and code (#19894) - laf
- Fix update ports error (#19874) - murrant
- Remove duplicate rrdtool version code (#19841) - murrant
- Rrd more robust error handling (#19840) - murrant
- Remove enable_footer config option (#19819) - laf
- Cisco port security code improvements (#19733) - murrant
Documentation
- Clarify interface parsing asymmetric speed (#19875) - murrant
- Minor improvement of Configuration doc (#19864) - takyanagida
- Update Distributed-Poller.md to reference billing module (#19474) - eduardomozart
- Additionally documentation for microsoft socialite roles (#19423) - Jannos-443
Translation
- German translation improvements #1 (#19855) - maggo1404
- Add Spanish (es) translation (#19834) - danpal-dev
- German translation improvements #2 (#19829) - maggo1404
- German translation improvements #3 (#19716) - maggo1404
Tests
Misc
- Add check_zone_auth override (#19632) - 49phil
- Add check_zone_rrsig_expiration override (#19629) - 49phil
- Cleanup set_dev_attrib (#19442) - mpikzink
Dependencies
- Bump esbuild, vite and laravel-vite-plugin (#19893) - dependabot
- Bump guzzlehttp/psr7 from 2.9.0 to 2.11.0 (#19887) - dependabot
- Rrdtool minimum version 1.5.5 (#19837) - murrant
- Bump axios from 1.15.2 to 1.16.0 (#19789) - dependabot
- Bump symfony/yaml from 7.4.10 to 7.4.12 (#19776) - dependabot
- Bump symfony/mailer from 7.4.8 to 7.4.12 (#19775) - dependabot
- Bump symfony/mime from 7.4.9 to 7.4.13 (#19774) - dependabot
- Bump symfony/http-kernel from 7.4.10 to 7.4.13 (#19773) - dependabot
- Bump symfony/routing from 7.4.9 to 7.4.13 (#19771) - dependabot
Security Fixes
- Removed XSS vulnerabilities from storage tables and various UI tables
- Added CSRF check to ajax_form.php
- Validated ajax/select/port filters against allowed values
- Enforced device‑permission checks for API endpoints (search_by_mac, add_eventlog)
- Prevented data leakage when host addition via API fails
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]