AI description
CVE-2026-39955 describes a pre-authentication SQL Injection vulnerability found in Cacti, an open-source performance and fault management framework. This flaw affects versions 1.2.30 and earlier of the software. The vulnerability specifically resides within the `graph_view.php` component, where an unanchored `FILTER_VALIDATE_REGEXP` function allows attackers to bypass input validation. By exploiting this weakness, remote unauthenticated attackers can inject malicious SQL payloads into the application's database layer through crafted input parameters. This issue has been addressed and fixed in Cacti version 1.2.31.
- Description
- Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. This issue has been fixed in version 1.2.31.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- cacti
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-89
- Hype score
- Not currently trending
⚠️ Vulnerabilidades en productos Cacti ❗ CVE-2026-39955 ❗ CVE-2026-39938 ❗ CVE-2026-39893 ➡️ Más info: https://t.co/dHCbR56BL3 https://t.co/FpwhCvIjS8
@CERTpy
7 Jul 2026
187 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ネットワーク監視フレームワーク Cactiに4件の脆弱性(CVE-2026-39893・CVE-2026-39955・CVE-2026-39938・CVE-2026-39951) https://t.co/QmXt5vJXUr #セキュリティ対策Lab #security #securitynews
@securityLab_jp
2 Jul 2026
112 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cactiで重大(Critical)な脆弱性4件が修正。CVE-2026-39893とCVE-2026-39948は、SQL RLIKE句を適切な無害化無しで組んでいたことによるSQLインジェクション。CVE-2026-39955は正規表現のアンカー欠如によるSQLインジェクション。
@__kokumoto
30 Jun 2026
875 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️⚠️ CVE-2026-39893 (CVSS 9.8) + CVE-2026-39948 (CVSS 9.8) + CVE-2026-39955 (CVSS 9.8) + CVE-2026-39938 (CVSS 9.8): Pre-auth SQLi and LFI in Cacti <=1.2.30 via graph_view.php; guest graph viewing can expose unauthenticated paths. 🔗FOFA Link: https://t.co/jTJEpmfiBV
@fofabot
30 Jun 2026
10161 Impressions
22 Retweets
83 Likes
37 Bookmarks
2 Replies
0 Quotes
Cacti vulnerabilities in 1.2.30 include pre-auth SQL injection and LFI, both CVSS 9.8 (CVE-2026-39955, CVE-2026-39938). Update to 1.2.31 now. #Cacti #SQLInjection #LFI #CVE #Cybersecurity #Infosec https://t.co/QJrq3ITZea https://t.co/RyOPac2ICl
@Daily_CyberSec
30 Jun 2026
785 Impressions
2 Retweets
8 Likes
3 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5406B2E1-D53C-45AC-8F93-CFCAEDC1B5F8",
"versionEndExcluding": "1.2.31",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]