Executive brief
Cacti, an open-source network monitoring and fault management framework, is vulnerable to an open redirect flaw during the login process. By tricking a user into clicking a specially crafted link, an attacker can redirect the user to a malicious external website immediately after they log in. This can be used in phishing campaigns to steal credentials or deliver malware by making the malicious site appear to be a legitimate part of the Cacti application.
Technical details
An open redirect vulnerability exists in Cacti's `auth_login_redirect()` function within `lib/auth.php`. The vulnerability stems from using a simple substring check (`str_contains`) on the `HTTP_REFERER` header against the `CACTI_PATH_URL` constant, rather than performing a proper host validation. If a user's profile is configured to redirect to the referer after login (`login_opts == '1'`), an attacker can provide a referer like `https://evil.com/cacti/` to bypass the check and force a redirection to an external domain. The fix, introduced in version 1.2.31, replaces the substring check with the `validate_redirect_url()` helper function which properly parses URLs and filters external hostnames.
Affected products
- Cacti Group Cacti <= 1.2.30
Timeline
- 2026-04-26: patched: Fix merged into 1.2.x branch via PR #7054
- 2026-06-15: advisory: Release of version 1.2.31 containing the fix
- 2026-06-25: disclosed: CVE-2026-40080 published