Security

How to report a vulnerability in NetXMS, and what happens after you do.

Last updated 2026-09-24

This page mirrors the security policy in the source repository, which is the canonical version.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues, the forum, or Telegram. Use one of these private channels:

Include as much of the following as you can:

  • Affected component (server, agent, subagent, management console, WebAPI, client library, etc.) and version
  • Type of issue (for example authentication bypass, injection, memory corruption, information disclosure)
  • Steps to reproduce, or a proof-of-concept
  • Impact assessment: what an attacker can achieve and under which preconditions (network position, required privileges)
  • Any suggested fix or mitigation, if you have one

You will receive an acknowledgement within a few business days. We will keep you informed of the progress towards a fix and may ask for additional information.

Coordinated disclosure

We ask reporters to give us reasonable time to investigate and release a fix before any public disclosure. We will work with you to agree on a disclosure date.

When a fix is released, we publish a GitHub Security Advisory and note the fix in the release notes. Reporters are credited in the advisory unless they prefer to remain anonymous.

Supported versions

Reports are accepted for any NetXMS version. Fixes are released for the currently maintained stable release series, 6.2 today; if you are running an older release, the fix will require an upgrade.

Enterprise Edition customers get fixes under the maintenance terms of their subscription; the editions page lists them.

No bug bounty

NetXMS does not run a bug bounty program and does not pay for vulnerability reports. Reporters are credited in the advisory, and that is the only reward on offer.

Scope

In scope: all code in the NetXMS repository, including the server (netxmsd), agent (nxagentd) and subagents, management console (nxmc), WebAPI, client libraries, and supporting libraries.

Out of scope:

  • Vulnerabilities in third-party dependencies that are not caused by how NetXMS uses them. Please report those to the upstream project.
  • Issues that require an already fully compromised host or administrator account on the NetXMS server.
  • Insecure deployments resulting from configuration choices that the documentation explicitly warns about.

If you are unsure whether something is in scope, report it anyway and we will make the call.

Verifying downloads

Every release file has a SHA256 checksum (.sha256) and a detached GPG signature (.asc) next to it, and repository packages are signed with the same key. The download page links both for each file and publishes the signing key.