CVE-2026-39893Patch(cacti / cacti)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cacti cacti systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into a RLIKE SQL clause without sanitization. The endpoint does not require authentication (graph viewing supports guest access via the configured guest user), so the SQLi was reachable pre-auth on installs with guest viewing enabled. This issue was fixed in version 1.2.31.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cacti

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Dislclosure: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-06-30); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
cacti

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Mentions · 2026-07-06: 1Mentions · 2026-07-07: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-06: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-01: 1Technical Details · 2026-07-06: 106-3007-0107-0207-0607-07
Signal classification4 categories
Patch
350.0%
Dislclosure
116.7%
Disclosure
116.7%
General
116.7%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-06-302
Dislclosure1Patch1
2026-07-011
Disclosure1
2026-07-021
Patch1
2026-07-061
Patch1
2026-07-071
General1
Full discourse6 posts
  • FOFA@fofabot
    Dislclosure

    ⚠️⚠️ CVE-2026-39893 (CVSS 9.8) + CVE-2026-39948 (CVSS 9.8) + CVE-2026-39955 (CVSS 9.8) + CVE-2026-39938 (CVSS 9.8): Pre-auth SQLi and LFI in Cacti <=1.2.30 via graph_view.php; guest graph viewing can expose unauthenticated paths. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJDYWN0aS1Nb25pdG9yaW5nIg== 🎯16.8K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Cacti-Monitoring" 🔖Refer: https://securityonline.info/cacti-vulnerabilities-1-2-31/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post publicly discloses four high‑severity SQLi and LFI vulnerabilities in Cacti, providing technical details and a FOFA link, but offers no proof‑of‑concepts, exploits, patches, or evidence of active exploitation.

    4270954014.7K
    14.7K followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-39893 (CVSS 9.8) & CVE-2026-39955 (CVSS 9.8) & CVE-2026-39938 (CVSS 9.8): Critical Pre-Authentication SQL Injection Vulnerabilities in Cacti. 📊19.4K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Cacti%22 👇Query HUNTER : http://product.name="Cacti" 📰Refer:https://github.com/Cacti/cacti/security/advisories/GHSA-69gg-mjfm-jjpc https://cyberpress.org/critical-cacti-vulnerabilities/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The notice announces three highly rated pre‑authentication SQL injection vulnerabilities (CVE‑2026‑39893, 39955, 39938) in Cacti, referencing official advisories but providing no PoC, exploit, or patch details.

    18045195.5K
    26.0K followersView on X
  • vulntoday@vulntoday
    Patch

    🔴 CRITICAL CVE-2026-39893 SQL injection (CWE-89) in the Cacti open-source network monitoring platform is resolved in version 1.2.31, distributed by Alpine Linux as cacti 1.2.31-0 and tracked upstream in Cacti PR #7039 and adv… https://vuln.today/cve/CVE-2026-39893 #CVE #infosec

    Post summary

    The post announces that CVE-2026-39893, a SQL injection flaw in Cacti, has been fixed in version 1.2.31 and distributed by Alpine Linux, with no mention of exploits or active attacks.

    2003056
    23 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cacti ❗ CVE-2026-39955 ❗ CVE-2026-39938 ❗ CVE-2026-39893 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cacti/ https://t.co/FpwhCvIjS8

    Post summary

    The tweet lists three CVE identifiers for Cacti products and provides a link for further information, but offers no additional technical or exploit details.

    00000218
    6.7K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    ネットワーク監視フレームワーク Cactiに4件の脆弱性(CVE-2026-39893・CVE-2026-39955・CVE-2026-39938・CVE-2026-39951) https://rocket-boys.co.jp/security-measures-lab/cacti-vulnerability-fix-cve-2026-39893/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The post announces four CVEs affecting the Cacti network monitoring framework and provides a link to a fix page, indicating patches are available.

    00000129
    454 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨🔧 Critical Cacti vulnerabilities expose servers to pre-auth SQL injection attacks 🔹 CVE-2026-39893 (CVSS 9.8) lets unauthenticated attackers exploit unsanitized input in graph_view.php via Cacti's guest-access feature 🔹 CVE-2026-39955 (CVSS 9.8) bypasses input validation, allowing unauthenticated SQL injection with full confidentiality/integrity/availability impact 🔹 CVE-2026-39938 (CVSS 9.8) enables unauthenticated local file inclusion via the graph_theme parameter 🔹 Admins should upgrade to Cacti 1.2.31 immediately, especially guest-accessible instances facing the two critical pre-auth flaws

    Post summary

    The post highlights critical pre‑auth vulnerabilities in Cacti, provides technical details and CVSS scores, and urges users to patch by upgrading to version 1.2.31.

    0000051
    22 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcacticacti---

Explore more