SQL injection in Cacti - CVE-2026-40083

 

SQL injection in Cacti - CVE-2026-40083

Published: June 22, 2026


Vulnerability identifier: #VU134993
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40083
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary SQL commands.

The vulnerability exists due to improper neutralization of special elements used in an SQL command in managers.php when processing crafted POST parameters for manager actions. A remote privileged user can submit a specially crafted selected_graphs_array value to execute arbitrary SQL commands.

Exploitation requires SNMP agent management permissions.


Affected software

Cacti

How to mitigate CVE-2026-40083

Install security update from vendor's website.

Cacti - update to 1.2.31

External References

Related Security Bulletins