CVE-2026-39951: Cacti is an open source performance and fault manageme
CVE-2026-39951 analysis covering impact, affected products, versions, remediation, and cross-checked defender guidance.
CVE-2026-39951 is a vulnerability published by NVD on 6/25/2026.
What happened
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph_name_regexp in the Reports feature. This issue has been fixed in version 1.2.31.
Affected products and versions
- cacti cacti unspecified version (before 1.2.31)
Severity and weakness
CVSS: HIGH 7.6. Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L.
Weaknesses: CWE-89.
Known exploitation
No CISA KEV entry is currently attached to the NVD record.
What defenders should do
- Identify whether the affected product and version range exists in production.
- Review vendor advisories and release notes before change windows.
- Patch, upgrade, disable the vulnerable component, or apply vendor mitigations.
- Verify the running version after deployment, not only the package inventory.
Official and supporting references
- https://github.com/Cacti/cacti/commit/4c09efaebf3a9faec66969d0b5c4aceaf397f37f
- https://github.com/Cacti/cacti/security/advisories/GHSA-pf37-v86f-5xwp