PT-2026-52128 · Cacti · Cacti

CVE-2026-39893

·

Published

2026-06-24

·

Updated

2026-07-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.31
Description An issue exists where the rfilter request variable is concatenated into a RLIKE SQL clause without proper sanitization. This allows for a pre-authentication SQL injection (SQLi) on installations where guest viewing is enabled, as the affected endpoint does not require authentication. The vulnerable endpoint is 'graph view.php'.
Recommendations Update to version 1.2.31. As a temporary mitigation, restrict guest access for graph viewing to prevent pre-authentication exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39893
GHSA-69GG-MJFM-JJPC

Affected Products

Cacti