SQL injection in Cacti - CVE-2026-40083
Published: June 22, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary SQL commands.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in managers.php when processing crafted POST parameters for manager actions. A remote privileged user can submit a specially crafted selected_graphs_array value to execute arbitrary SQL commands.
Exploitation requires SNMP agent management permissions.