Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-39955: Cacti versions 1.2.30 and prior allow unauthorized access

CVE-2026-39955
Summary

Cacti, a performance management tool, has a security flaw that could let attackers access sensitive data without proper authorization. This issue has been fixed in version 1.2.31, so it's recommended to update to the latest version to prevent unauthorized access.

Original title
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. This iss...
Original description
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. This issue has been fixed in version 1.2.31.
nvd CVSS3.1 9.8
Vulnerability type
CWE-89 SQL Injection
Published: 24 Jun 2026 · Updated: 23 Jul 2026 · First seen: 24 Jun 2026