SQL Injection Vulnerability in Cacti Performance Management Framework
CVE-2026-39948
9.3CRITICAL
What is CVE-2026-39948?
The vulnerability in Cacti arises from the inadequate sanitization of the rfilter request parameter in versions prior to 1.2.31. An attacker can exploit this flaw by injecting arbitrary SQL statements into the application's SQL queries, potentially leading to unauthorized access and manipulation of the database. This issue is particularly severe when guest graph viewing is enabled, as it allows unauthenticated attacks through accessible endpoints. The flaw is a significant risk to the confidentiality, integrity, and availability of sensitive database information, highlighting the importance of upgrading to the latest version to safeguard against such exploits.
Affected Version(s)
cacti < 1.2.31
