PT-2026-52628 · Cacti · Cacti

·

CVE-2026-40941

·

Published

2026-04-17

·

Updated

2026-06-29

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.31
Description Cacti is an open source performance and fault management framework. The software contains a package import signature validation bypass that allows the use of self-signed packages.
Recommendations Update to version 1.2.31.

Exploit

Fix

DoS

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09121
CVE-2026-40941
GHSA-274C-97HJ-PV2V

Affected Products

Cacti