CVE-2026-39938: Cacti: Unauthenticated RCE on Graph Image
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graphtheme and rrdtool IPC serialization hardening. This issue has been resolved in version 1.2.31.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cactito a version that resolves this vulnerability.Fixed in 1.2.31 - Compensating control
For Cacti versions 1.2.30 and prior, mitigate the unauthenticated LFI via graph_theme and rrdtool IPC serialization exposure until upgrading to 1.2.31 (the issue is resolved in 1.2.31).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39938?
CVE-2026-39938 has a critical severity score of 9.8.
How do I fix CVE-2026-39938?
To mitigate CVE-2026-39938, upgrade Cacti to version 1.2.31 or later.
What types of attacks does CVE-2026-39938 enable?
CVE-2026-39938 allows for unauthenticated remote code execution through path traversal vulnerabilities.
Which versions of Cacti are affected by CVE-2026-39938?
Cacti versions 1.2.30 and prior are affected by CVE-2026-39938.
What is the impact of CVE-2026-39938?
The impact of CVE-2026-39938 includes potential unauthorized access and control over the system, allowing attackers to execute arbitrary code.