CVE-2026-39938

Published Jun 24, 2026

Last updated 2 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-39938 identifies an unauthenticated Local File Inclusion (LFI) vulnerability affecting Cacti, an open-source performance and fault management framework. This flaw is present in versions 1.2.30 and earlier of the software. The vulnerability arises from insufficient input validation within the `graph_theme` and `rrdtool` IPC serialization components. Exploitation of CVE-2026-39938 allows remote attackers to manipulate file inclusion parameters without requiring any authentication credentials. This can enable unauthorized access to arbitrary files on the system, potentially exposing sensitive information such as configuration files, database credentials, and other internal system data. The issue has been resolved in Cacti version 1.2.31.

Description
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This issue has been resolved in version 1.2.31.
Source
security-advisories@github.com
NVD status
Analyzed
Products
cacti

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-22

Social media

Hype score
Not currently trending
  1. ⚠️ Vulnerabilidades en productos Cacti ❗ CVE-2026-39955 ❗ CVE-2026-39938 ❗ CVE-2026-39893 ➡️ Más info: https://t.co/dHCbR56BL3 https://t.co/FpwhCvIjS8

    @CERTpy

    7 Jul 2026

    187 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ネットワーク監視フレームワーク Cactiに4件の脆弱性(CVE-2026-39893・CVE-2026-39955・CVE-2026-39938・CVE-2026-39951) https://t.co/QmXt5vJXUr #セキュリティ対策Lab #security #securitynews

    @securityLab_jp

    2 Jul 2026

    112 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Cactiで重大(Critical)な脆弱性4件が修正。CVE-2026-39893とCVE-2026-39948は、SQL RLIKE句を適切な無害化無しで組んでいたことによるSQLインジェクション。CVE-2026-39955は正規表現のアンカー欠如によるSQLインジェクション。

    @__kokumoto

    30 Jun 2026

    875 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ⚠️⚠️ CVE-2026-39893 (CVSS 9.8) + CVE-2026-39948 (CVSS 9.8) + CVE-2026-39955 (CVSS 9.8) + CVE-2026-39938 (CVSS 9.8): Pre-auth SQLi and LFI in Cacti <=1.2.30 via graph_view.php; guest graph viewing can expose unauthenticated paths. 🔗FOFA Link: https://t.co/jTJEpmfiBV

    @fofabot

    30 Jun 2026

    10161 Impressions

    22 Retweets

    83 Likes

    37 Bookmarks

    2 Replies

    0 Quotes

  5. Cacti vulnerabilities in 1.2.30 include pre-auth SQL injection and LFI, both CVSS 9.8 (CVE-2026-39955, CVE-2026-39938). Update to 1.2.31 now. #Cacti #SQLInjection #LFI #CVE #Cybersecurity #Infosec https://t.co/QJrq3ITZea https://t.co/RyOPac2ICl

    @Daily_CyberSec

    30 Jun 2026

    785 Impressions

    2 Retweets

    8 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  6. Top CVEs w/ public exploits (Jun 20–27): CVE-2026-48908 Joomla SPB RCE (exploited live) CVE-2026-48909 Joomla SP LMS PHP Obj injection CVE-2026-12417 SignUp/In admin takeover CVE-2026-12416 Invoice Generator takeover CVE-2026-39938 Cacti LFI Protect via https://t.co/ZUTqqMjQUp

    @exploitgrid

    27 Jun 2026

    1601 Impressions

    4 Retweets

    19 Likes

    7 Bookmarks

    2 Replies

    0 Quotes

Configurations