CVE-2026-39951Disclosure(cacti / cacti)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cacti cacti systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph_name_regexp in the Reports feature. This issue has been fixed in version 1.2.31.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cacti

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-06-25); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
cacti

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-06-25: 4Mentions · 2026-07-02: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-06-25: 406-2507-02
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-254
Disclosure2General1Patch1
2026-07-021
Patch1
Full discourse5 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-39951 - #SQLi in #Cacti. Stored injection via graph_name_regexp in Reports. #CVSS 7.6. Update to v1.2.31 immediately. #infosec #Cvealert #cybersecurity more detailed info: https://www.valtersit.com/cve/CVE-2026-39951

    Post summary

    CVE-2026-39951 is a stored SQL injection flaw in Cacti’s graph_name_regexp in Reports with a CVSS score of 7.6. Users should apply the v1.2.31 update immediately to mitigate the risk.

    0001084
    965 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    ネットワーク監視フレームワーク Cactiに4件の脆弱性(CVE-2026-39893・CVE-2026-39955・CVE-2026-39938・CVE-2026-39951) https://rocket-boys.co.jp/security-measures-lab/cacti-vulnerability-fix-cve-2026-39893/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The tweet announces four Cacti vulnerabilities and links to a page containing fix information for CVE-2026-39893, indicating patch material is available.

    00000129
    454 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-39951 Stored SQL Injection in Cacti Through Graph Name Regexp Reports Feature https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39951

    Post summary

    The entry reports CVE‑2026‑39951 as a stored SQL injection flaw in Cacti's Graph Name Regexp Reports feature, but offers no concrete PoC, exploit code, patch, or evidence of active exploitation.

    00000111
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-39951 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph_name_regexp in t… https://www.cve.org/CVERecord?id=CVE-2026-39951 ----- Traducción: CVE-2026-39951 Cac… http://infoflow.cloud`

    Post summary

    Public disclosure of a stored SQL injection vulnerability in Cacti 1.2.30 and earlier, with no mention of PoC, fixes, or active exploitation.

    0000042
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39951 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph_name_regexp in t… https://www.cve.org/CVERecord?id=CVE-2026-39951

    Post summary

    The text announces a stored SQL injection flaw in Cacti 1.2.30 and earlier, linking to the CVE record.

    00000665
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcacticacti---

Explore more