Observable Response Discrepancy in Cacti - CVE-2026-49442

 

Observable Response Discrepancy in Cacti - CVE-2026-49442

Published: June 22, 2026


Vulnerability identifier: #VU134992
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-49442
CWE-ID: CWE-204
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to enumerate valid usernames.

The vulnerability exists due to observable response discrepancy in the login page when handling login attempts. A remote attacker can submit login requests with different usernames to enumerate valid usernames.

The responses differ only by the capitalization of the word "failed" in the error message.


Affected software

Cacti

How to mitigate CVE-2026-49442

Install security update from vendor's website.

Cacti - update to 1.2.31

External References

Related Security Bulletins