CVE-2026-40079Disclosure(cacti / cacti)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The escape_command() function at lib/rrd.php is a no-op: it returns $command unchanged. The command line built by rrdtool_function_graph() is passed through this function and then to shell_exec($full_commandline). The risk is in __rrd_execute() where text_format values from graph templates (which may contain host variable substitutions) reach shell_exec without adequate escaping. This issue has been addressed in version 1.2.31.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-88

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cacti

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-06-25); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
cacti

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-06-25: 3Mentions · 2026-07-20: 1PoC Mentioned / Linked · 2026-06-25: 1Technical Details · 2026-06-25: 3Technical Details · 2026-07-20: 106-2507-20
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-253
Disclosure3
2026-07-201
Disclosure1
Full discourse4 posts
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-40079: Cacti Command Injection Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04q30Yr0

    Post summary

    The headline announces CVE‑2026‑40079, a command‑injection flaw in Cacti, and promises guidance on how businesses should respond.

    0000028
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40079 Command Injection in Cacti Versions 1.2.30 and Prior via Unsanitized escape_command() Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40079

    Post summary

    CVE-2026-40079 is a command injection vulnerability in older Cacti versions stemming from an unsanitized escape_command() function. The post provides a link to general details but does not mention exploits, patches, or active exploitation.

    00000119
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40079 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the e… https://www.cve.org/CVERecord?id=CVE-2026-40079 ----- Traducción: CVE-2026-40079 Cac… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-40079 as a command injection flaw in Cacti 1.2.30 and earlier, noting a sanitization issue, but it provides no PoC, exploit, or patch information.

    0000040
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40079 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the e… https://www.cve.org/CVERecord?id=CVE-2026-40079

    Post summary

    The text announces CVE-2026-40079 affects Cacti 1.2.30 and earlier, describing a command injection flaw caused by unsanitized input.

    00000712
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcacticacti---

Explore more