Junglewise Threat Intelligence

CVE-2026-40941: Cacti package import signature validation bypass

CVE-2026-40941 · Severity: info · CVSS 7.1 · Published 2026-06-25

Technologies: Cacti. Vendors: Cacti.

Executive brief

Cacti, an open-source network monitoring and fault management framework, contains a security flaw in how it handles imported packages. The system fails to properly validate cryptographic signatures, which could allow an attacker to upload and install unauthorized or malicious "self-signed" packages. This could lead to unauthorized configuration changes or the introduction of malicious code into the monitoring environment.

Technical details

A vulnerability exists in Cacti's package import mechanism (lib/import.php) due to improper verification of cryptographic signatures (CWE-347). The flaw allows the system to accept self-signed packages that have not been verified against a trusted authority. An authenticated attacker with low privileges can exploit this bypass to import arbitrary packages, potentially leading to unauthorized modifications of the Cacti environment. This issue was addressed in version 1.2.31 by tightening package file allowlists and implementing anchored prefix policies for scripts and resources.

Affected products

  • Cacti Cacti <= 1.2.30

Timeline

  • 2026-06-15: patched: Version 1.2.31 released
  • 2026-06-18: advisory: GitHub Security Advisory GHSA-274c-97hj-pv2v published
  • 2026-06-25: disclosed: CVE-2026-40941 published to NVD

References

Related threats