Junglewise Threat Intelligence

CVE-2026-39948: Cacti SQL injection in rfilter parameter

CVE-2026-39948 · Severity: info · CVSS 9.3 · Published 2026-06-24

Technologies: Cacti. Vendors: Cacti.

Executive brief

Cacti is an open-source platform used by IT teams to monitor network performance and graph system data. A security flaw allows an unauthenticated attacker to execute unauthorized database commands by sending a specially crafted web request. This could lead to the theft of sensitive configuration data, modification of system records, or full compromise of the monitoring database.

Technical details

An unauthenticated SQL injection vulnerability exists in Cacti versions 1.2.30 and prior due to improper neutralization of the 'rfilter' request parameter. The application uses the raw accessor grv() instead of the filtered gfrv() function, allowing input to be concatenated directly into RLIKE SQL clauses within lib/html_graph.php and lib/html_tree.php. This path is reachable without authentication via graph_view.php on systems where guest graph viewing is enabled. An attacker can use unbalanced-quote payloads to bypass regex validation and execute arbitrary SQL commands. The issue is resolved in version 1.2.31 by implementing proper quoting via db_qstr_rlike().

Affected products

  • Cacti Cacti <= 1.2.30

Timeline

  • 2026-06-19: advisory: GitHub Security Advisory GHSA-9jqv-4cpm-vm2c published
  • 2026-06-24: disclosed: CVE-2026-39948 published to NVD
  • 2026-06-24: patched: Fix committed in version 1.2.31

References

Related threats