Improper Verification of Cryptographic Signature in Cacti - CVE-2026-40941
Published: June 19, 2026
Cacti
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass package signature validation and import self-signed packages.
The vulnerability exists due to improper verification of cryptographic signature in the package import signature validation mechanism when processing package imports. A remote attacker can supply a self-signed package to bypass package signature validation and import self-signed packages.