Executive brief
Cacti is an open-source platform used by organizations to monitor network performance and manage IT infrastructure. A critical security flaw allows unauthenticated remote attackers to access sensitive files on the server or potentially execute malicious commands. This could lead to a total system takeover, data theft, or disruption of monitoring services.
Technical details
A Local File Inclusion (LFI) and OS Command Injection vulnerability exists in Cacti versions 1.2.30 and prior. The flaw is rooted in the 'graph_theme' parameter within 'lib/rrd.php', where user-supplied input is used to construct file paths without sufficient validation. While an initial fix attempted to use 'basename()', it was found to be bypassable, leading to a more robust fix involving 'cacti_validate_theme()' and filesystem-allowlist validation. An unauthenticated attacker can exploit this over the network to include arbitrary files or inject commands via rrdtool IPC serialization, resulting in full system compromise. Users should upgrade to version 1.2.31.
Affected products
- Cacti Group Cacti <= 1.2.30
Timeline
- 2026-04-17: other: Vulnerability reviewed in session
- 2026-06-19: advisory: GitHub Security Advisory published
- 2026-06-24: disclosed: CVE published to NVD