CVE-2026-39955: Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php
Published Jun 24, 2026
·Updated
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTERVALIDATEREGEXP in graphview.php. This issue has been fixed in version 1.2.31.
Affected Software
2 affected components
Cacti Cacti<=1.2.30
Cacti Cacti<1.2.31
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
cactito a version that resolves this vulnerability.Fixed in 1.2.31
Event History
Jun 24, 2026
CVE Published
via MITRE·10:49 PM
Data Sourced
via MITRE·10:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-39955?
CVE-2026-39955 has a critical severity rating of 9.8.
2
How do I fix CVE-2026-39955?
To fix CVE-2026-39955, upgrade to Cacti version 1.2.31 or later.
3
What type of vulnerability is CVE-2026-39955?
CVE-2026-39955 is a pre-authentication SQL Injection vulnerability.
4
Which versions of Cacti are affected by CVE-2026-39955?
Cacti versions 1.2.30 and prior are affected by CVE-2026-39955.
5
Where does CVE-2026-39955 occur in Cacti?
CVE-2026-39955 occurs in the graph_view.php file of Cacti.