Command Injection Vulnerability in Cacti Performance Management Framework
CVE-2026-40079

8.6HIGH

Key Information:

Vendor

Cacti

Status
Vendor
CVE Published:
24 June 2026

What is CVE-2026-40079?

Cacti, a widely-used open source performance and fault management framework, is susceptible to command injection due to insufficient sanitization in the escape_command() function. This vulnerability allows an attacker to execute arbitrary commands on the host system. The command line generated by the rrdtool_function_graph() function is improperly sanitized, allowing potentially unsafe text_format values from graph templates to reach the shell_exec() function unchecked. The issue has been resolved in version 1.2.31, highlighting the importance of updating to secure versions to mitigate risks.

Affected Version(s)

cacti < 1.2.31

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.