CVE-2026-39951: Cacti: Stored SQL Injection via graph_name_regexp in Reports feature
Published Jun 24, 2026
·Updated
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graphnameregexp in the Reports feature. This issue has been fixed in version 1.2.31.
Affected Software
2 affected components
Cacti Cacti<=1.2.30
Cacti Cacti<1.2.31
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
cactito a version that resolves this vulnerability.Fixed in 1.2.31
Event History
Jun 24, 2026
CVE Published
via MITRE·11:14 PM
Data Sourced
via MITRE·11:14 PM
DescriptionSeverityWeakness
Jun 25, 2026
Data Sourced
via NVD·12:17 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-39951?
The severity of CVE-2026-39951 is rated as high with a score of 7.6.
2
How do I fix CVE-2026-39951?
CVE-2026-39951 can be fixed by upgrading to Cacti version 1.2.31 or later.
3
What type of vulnerability is CVE-2026-39951?
CVE-2026-39951 is classified as a Stored SQL Injection vulnerability.
4
Which feature of Cacti is affected by CVE-2026-39951?
CVE-2026-39951 affects the Reports feature via the graph_name_regexp.
5
What versions of Cacti are impacted by CVE-2026-39951?
Cacti versions 1.2.30 and prior are impacted by CVE-2026-39951.