Junglewise Threat Intelligence

CVE-2026-40080: Cacti open redirect in auth_login_redirect

CVE-2026-40080 · Severity: medium · CVSS 6.1 · Published 2026-06-25

Technologies: Cacti Group Cacti.

Executive brief

Cacti, an open-source network monitoring and fault management framework, is vulnerable to an open redirect flaw during the login process. By tricking a user into clicking a specially crafted link, an attacker can redirect the user to a malicious external website immediately after they log in. This can be used in phishing campaigns to steal credentials or deliver malware by making the malicious site appear to be a legitimate part of the Cacti application.

Technical details

An open redirect vulnerability exists in Cacti's `auth_login_redirect()` function within `lib/auth.php`. The vulnerability stems from using a simple substring check (`str_contains`) on the `HTTP_REFERER` header against the `CACTI_PATH_URL` constant, rather than performing a proper host validation. If a user's profile is configured to redirect to the referer after login (`login_opts == '1'`), an attacker can provide a referer like `https://evil.com/cacti/` to bypass the check and force a redirection to an external domain. The fix, introduced in version 1.2.31, replaces the substring check with the `validate_redirect_url()` helper function which properly parses URLs and filters external hostnames.

Affected products

  • Cacti Group Cacti <= 1.2.30

Timeline

  • 2026-04-26: patched: Fix merged into 1.2.x branch via PR #7054
  • 2026-06-15: advisory: Release of version 1.2.31 containing the fix
  • 2026-06-25: disclosed: CVE-2026-40080 published

References