Use of Function with Inconsistent Implementations in Cacti - CVE-2026-39894
Published: June 19, 2026
Cacti
Detailed vulnerability description
The vulnerability allows a remote attacker to corrupt metric values.
The vulnerability exists due to use of function with inconsistent implementations in rrdtool_function_update() when formatting numeric metric values for RRDtool updates. A remote attacker can cause locale-sensitive comma decimal formatting to be used to corrupt metric values.
Exploitation requires the server to use an LC_NUMERIC locale with a comma decimal separator.