PT-2026-52135 · Cacti · Cacti

·

CVE-2026-39900

·

Published

2026-06-24

·

Updated

2026-06-25

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.31
Description Reflected Cross-Site Scripting (XSS) occurs in the JavaScript context of the 'auth profile.php' endpoint through the tab parameter. Reflected XSS is a type of attack where a malicious script is reflected off a web application to the victim's browser.
Recommendations Update to version 1.2.31. As a temporary workaround, restrict access to the 'auth profile.php' endpoint or avoid using the tab parameter until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39900
GHSA-34RF-FRC3-V48R

Affected Products

Cacti