PT-2026-52627 · Cacti · Cacti

·

CVE-2026-40084

·

Published

2026-04-12

·

Updated

2026-06-29

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.31
Description Cacti is an open source performance and fault management framework. A path traversal issue allows for arbitrary file read through the Report format file parameter. The process occurs in two stages: first, a stored injection where lib/html reports.php stores the format file value into the database without validation; second, lib/reports.php concatenates the value with a path and uses the file() function to read arbitrary files from the filesystem.
Recommendations Update to version 1.2.31.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09120
CVE-2026-40084
GHSA-MJVW-MHJ5-9JCJ

Affected Products

Cacti