SQL injection in Cacti - CVE-2026-39893
Published: June 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL commands.
The vulnerability exists due to SQL injection in graph_view.php when processing the rfilter request variable in graph filter requests. A remote attacker can send a specially crafted request to execute arbitrary SQL commands.
The issue is reachable without authentication on installations with guest viewing enabled.