Stored SQL Injection in Cacti Performance Management Framework
CVE-2026-39951
7.6HIGH
What is CVE-2026-39951?
Cacti, an open source performance and fault management framework, is susceptible to a Stored SQL Injection vulnerability that affects versions 1.2.30 and earlier through the graph_name_regexp parameter within its Reports feature. This issue could allow attackers to manipulate SQL queries executed by the application, potentially compromising the integrity and confidentiality of the underlying database. The vulnerability has been addressed in version 1.2.31, which is strongly recommended for users to protect against exploitation. For more details and mitigation steps, please refer to the official security advisory.
Affected Version(s)
cacti < 1.2.31
