Open redirect in Cacti - CVE-2026-40080

 

Open redirect in Cacti - CVE-2026-40080

Published: June 22, 2026


Vulnerability identifier: #VU134989
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40080
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect users to an untrusted site.

The vulnerability exists due to improper input validation in auth_login_redirect() in lib/auth.php when processing the HTTP_REFERER value during the login flow. A remote attacker can supply a crafted referer value to redirect users to an untrusted site.

User interaction is required, and the issue occurs when the user's login option is set to redirect to the referer after login.


Affected software

Cacti

How to mitigate CVE-2026-40080

Install security update from vendor's website.

Cacti - update to 1.2.31

External References

Related Security Bulletins