CVE-2026-39955
Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php
Description
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. This issue has been fixed in version 1.2.31.
In plain language
AI Worth attentionCacti (up to 1.2.30) has a serious database vulnerability that can be triggered over the network without logging in, so a typical small business using it should update to 1.2.31 or later as soon as possible.
CVE-2026-39955 is a pre-authentication SQL injection in Cacti’s graph_view.php (caused by an unanchored FILTER_VALIDATE_REGEXP), allowing attackers to execute unauthorized SQL over the network without any login.
What to do now
- Check your Cacti version and confirm whether you are running Cacti 1.2.30 or earlier.
- If you are affected, upgrade Cacti to 1.2.31 (or later).
- After upgrading, review Cacti and web server logs for suspicious requests targeting graph_view.php.
- If you cannot upgrade immediately, restrict network access to Cacti so it is not reachable from the public internet.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-39955 and every CVE in our database. Create a free account — no credit card required.
Create Free Account