CVE-2026-39893
EUVD-2026-3913124.06.2026, 22:16
Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into a RLIKE SQL clause without sanitization. The endpoint does not require authentication (graph viewing supports guest access via the configured guest user), so the SQLi was reachable pre-auth on installs with guest viewing enabled. This issue was fixed in version 1.2.31.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cacti | cacti | 𝑥 < 1.2.31 |
𝑥
= Vulnerable software versions
Debian Releases
Vulnerability Media Exposure