SQL Injection Vulnerability in Cacti Performance Management Framework
CVE-2026-39948

9.3CRITICAL

Key Information:

Vendor

Cacti

Status
Vendor
CVE Published:
24 June 2026

What is CVE-2026-39948?

The vulnerability in Cacti arises from the inadequate sanitization of the rfilter request parameter in versions prior to 1.2.31. An attacker can exploit this flaw by injecting arbitrary SQL statements into the application's SQL queries, potentially leading to unauthorized access and manipulation of the database. This issue is particularly severe when guest graph viewing is enabled, as it allows unauthenticated attacks through accessible endpoints. The flaw is a significant risk to the confidentiality, integrity, and availability of sensitive database information, highlighting the importance of upgrading to the latest version to safeguard against such exploits.

Affected Version(s)

cacti < 1.2.31

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.