Junglewise Threat Intelligence

CVE-2026-39897: Cacti reflected XSS in html_auth_footer

CVE-2026-39897 · Severity: info · CVSS 5.3 · Published 2026-06-24

Technologies: Cacti. Vendors: Cacti.

Executive brief

Cacti, an open-source network monitoring and fault management framework, contains a security vulnerability in its authentication footer component. An attacker could use this flaw to execute malicious scripts in a user's browser if the user clicks a specially crafted link. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Cacti versions <= 1.2.30 within the html_auth_footer function. The vulnerability stems from improper neutralization of user-controllable input before it is rendered in the authentication footer's error message output. An unauthenticated remote attacker can exploit this by enticing a user to visit a malicious URL, allowing the execution of arbitrary JavaScript in the context of the victim's browser session. This was identified during an internal audit and is addressed in version 1.2.31 by implementing proper output encoding and input validation.

Affected products

  • Cacti Cacti <= 1.2.30

Timeline

  • 2026-03-29: patched: Fix committed to repository
  • 2026-06-18: advisory: GitHub Security Advisory published
  • 2026-06-24: disclosed: CVE published to NVD

References

Related threats