PT-2026-52625 · Cacti · Cacti

·

CVE-2026-40082

·

Published

2026-04-30

·

Updated

2026-06-29

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.31
Description Cacti is an open source performance and fault management framework. The software is subject to Session Fixation because the session regenerate id() function is not called after a successful login. In the login flow at the 'auth login.php' endpoint, the system directly sets the $ SESSION[SESS USER ID] variable without rotating the session ID. While session cookie configurations include httponly, samesite, and secure flags, these measures do not prevent session fixation via same-site vectors.
Recommendations Update to version 1.2.31.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09118
CVE-2026-40082
GHSA-273R-QR93-WGCP

Affected Products

Cacti