CVE-2026-39899: Cacti: Path Traversal via filename parameter in package_import.php
Published Jun 24, 2026
·Updated
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter in packageimport.php. This issue has been fixed in version 1.2.31.
Affected Software
2 affected components
Cacti Cacti<=1.2.30
Cacti Cacti<1.2.31
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
cactito a version that resolves this vulnerability.Fixed in 1.2.31
Event History
Jun 24, 2026
CVE Published
via MITRE·10:33 PM
Data Sourced
via MITRE·10:33 PM
DescriptionWeakness
Data Sourced
via NVD·11:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-39899?
CVE-2026-39899 has a medium severity rating of 6.9 according to the CVSS v3.1 scoring system.
2
How do I fix CVE-2026-39899?
To fix CVE-2026-39899, upgrade to Cacti version 1.2.31 or later.
3
What type of vulnerability is CVE-2026-39899?
CVE-2026-39899 is classified as a Path Traversal vulnerability.
4
Which versions of Cacti are affected by CVE-2026-39899?
CVE-2026-39899 affects Cacti versions 1.2.30 and prior.
5
What component of Cacti is impacted by CVE-2026-39899?
CVE-2026-39899 impacts the package_import.php component of Cacti.