Cacti · Cacti · CVE-2026-39938
**Name of the Vulnerable Software and Affected Versions**
Cacti versions prior to 1.2.31
**Description**
Cacti is an open source performance and fault management framework. The software contains an unauthenticated Local File Inclusion (LFI), which occurs through the `graph theme` parameter and rrdtool IPC serialization hardening. LFI is a type of vulnerability that allows an attacker to read files on the server that they should not have access to.
**Recommendations**
Update to version 1.2.31.