Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-39938: Cacti versions 1.2.30 and prior allow unauthorized data access
CVE-2026-39938
Summary
Cacti, a performance and fault management tool, has a security issue that allows unauthorized users to access sensitive data. This issue affects versions 1.2.30 and earlier, but it has been fixed in version 1.2.31. To stay secure, update to the latest version of Cacti.
Original title
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This issue has be...
Original description
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This issue has been resolved in version 1.2.31.
nvd CVSS3.1
9.8
Vulnerability type
CWE-22
Path Traversal
CWE-78
OS Command Injection
Published: 24 Jun 2026 · Updated: 23 Jul 2026 · First seen: 24 Jun 2026