CVE-2026-39955Disclosure(cacti / cacti)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cacti cacti systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. This issue has been fixed in version 1.2.31.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cacti

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-06-30); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
cacti

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-06-25: 1Mentions · 2026-06-30: 3Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Mentions · 2026-07-07: 1Patch / Workaround · 2026-06-30: 2Technical Details · 2026-06-25: 1Technical Details · 2026-06-30: 3Technical Details · 2026-07-01: 106-2506-3007-0107-0207-07
Signal classification3 categories
Disclosure
571.4%
Patch
114.3%
General
114.3%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-06-251
Disclosure1
2026-06-303
Disclosure2Patch1
2026-07-011
Disclosure1
2026-07-021
Disclosure1
2026-07-071
General1
Full discourse7 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-39893 (CVSS 9.8) + CVE-2026-39948 (CVSS 9.8) + CVE-2026-39955 (CVSS 9.8) + CVE-2026-39938 (CVSS 9.8): Pre-auth SQLi and LFI in Cacti <=1.2.30 via graph_view.php; guest graph viewing can expose unauthenticated paths. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJDYWN0aS1Nb25pdG9yaW5nIg== 🎯16.8K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Cacti-Monitoring" 🔖Refer: https://securityonline.info/cacti-vulnerabilities-1-2-31/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces four high‑CVSS vulnerabilities (CVE‑2026‑39893, ‑39948, ‑39955, ‑39938) in Cacti <=1.2.30, detailing pre‑authentication SQL injection and local file inclusion via graph_view.php. While FOFA queries and references are provided, no PoC, active exploitation, or patch information is included.

    4270954014.7K
    14.7K followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-39893 (CVSS 9.8) & CVE-2026-39955 (CVSS 9.8) & CVE-2026-39938 (CVSS 9.8): Critical Pre-Authentication SQL Injection Vulnerabilities in Cacti. 📊19.4K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Cacti%22 👇Query HUNTER : http://product.name="Cacti" 📰Refer:https://github.com/Cacti/cacti/security/advisories/GHSA-69gg-mjfm-jjpc https://cyberpress.org/critical-cacti-vulnerabilities/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The tweet announces the discovery of three high‑severity, pre‑authentication SQL injection vulnerabilities in Cacti (CVE‑2026‑39893, CVE‑2026‑39955, CVE‑2026‑39938) with CVSS 9.8, yet provides no PoC, exploit, or patch information.

    18045195.5K
    26.0K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Cacti vulnerabilities in 1.2.30 include pre-auth SQL injection and LFI, both CVSS 9.8 (CVE-2026-39955, CVE-2026-39938). Update to 1.2.31 now. #Cacti #SQLInjection #LFI #CVE #Cybersecurity #Infosec https://securityonline.info/cacti-vulnerabilities-1-2-31 https://t.co/RyOPac2ICl

    Post summary

    The message highlights that Cacti v1.2.30 has high‑severity pre‑auth SQL injection and LFI flaws and urges users to update to 1.2.31 to remediate.

    02073893
    12.9K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cacti ❗ CVE-2026-39955 ❗ CVE-2026-39938 ❗ CVE-2026-39893 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cacti/ https://t.co/FpwhCvIjS8

    Post summary

    The post lists three CVE identifiers for vulnerabilities in Cacti products and provides links for further information.

    00000218
    6.7K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    ネットワーク監視フレームワーク Cactiに4件の脆弱性(CVE-2026-39893・CVE-2026-39955・CVE-2026-39938・CVE-2026-39951) https://rocket-boys.co.jp/security-measures-lab/cacti-vulnerability-fix-cve-2026-39893/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The post alerts that four new CVEs affect Cacti, a network monitoring framework, and provides a link that likely contains further details or fixes.

    00000129
    454 followersView on X
  • TECHEPAGES@techepages
    Disclosure

    🚨🔧 Critical Cacti vulnerabilities expose servers to pre-auth SQL injection attacks 🔹 CVE-2026-39893 (CVSS 9.8) lets unauthenticated attackers exploit unsanitized input in graph_view.php via Cacti's guest-access feature 🔹 CVE-2026-39955 (CVSS 9.8) bypasses input validation, allowing unauthenticated SQL injection with full confidentiality/integrity/availability impact 🔹 CVE-2026-39938 (CVSS 9.8) enables unauthenticated local file inclusion via the graph_theme parameter 🔹 Admins should upgrade to Cacti 1.2.31 immediately, especially guest-accessible instances facing the two critical pre-auth flaws

    Post summary

    The post announces three critical Cacti CVEs (CVE-2026-39893, CVE-2026-39955, CVE-2026-39938) that enable unauthenticated SQL injections and local file inclusion via the guest-access feature, and urges admins to immediately upgrade to Cacti 1.2.31.

    0000051
    22 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39955 Pre-Authentication SQL Injection in Cacti 1.2.30 and Prior Versions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39955

    Post summary

    CVE-2026-39955 is a pre‑authentication SQL injection vulnerability affecting Cacti 1.2.30 and earlier.

    00000109
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcacticacti---

Explore more