PT-2026-52128 · Cacti · Cacti
CVE-2026-39893
·
Published
2026-06-24
·
Updated
2026-07-01
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cacti versions prior to 1.2.31
Description
An issue exists where the
rfilter request variable is concatenated into a RLIKE SQL clause without proper sanitization. This allows for a pre-authentication SQL injection (SQLi) on installations where guest viewing is enabled, as the affected endpoint does not require authentication. The vulnerable endpoint is 'graph view.php'.Recommendations
Update to version 1.2.31.
As a temporary mitigation, restrict guest access for graph viewing to prevent pre-authentication exploitation.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cacti