Cross-site scripting in Cacti - CVE-2026-39900
Published: June 19, 2026
Cacti
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.
The vulnerability exists due to cross-site scripting in auth_profile.php when processing the tab parameter in a JavaScript string context. A remote attacker can send a specially crafted request to execute arbitrary script in the victim's browser.