PT-2026-52626 · Cacti · Cacti

·

CVE-2026-40083

·

Published

2026-04-18

·

Updated

2026-08-27

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.31
Description An issue exists in the performance and fault management framework where improper handling of deserialized data leads to SQL Injection. In the 'managers.php' file, the application processes the selected graphs array variable using a custom unserialize function. While object injection is prevented, arbitrary string arrays can still be deserialized. These values are subsequently passed to the db execute() function and merged into a SQL DELETE statement via an implode operation without integer validation. This allows for SQL Injection when utilizing SNMP agent management permissions.
Recommendations Update to version 1.2.31.

Exploit

Fix

DoS

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09116
CVE-2026-40083
GHSA-J9JV-6XJQ-9HHJ

Affected Products

Cacti