CVE-2026-40941: Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cactito a version that resolves this vulnerability.Fixed in 1.2.31
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40941?
CVE-2026-40941 has a severity rating of 7.1, which falls into the high severity category.
How do I fix CVE-2026-40941?
To fix CVE-2026-40941, upgrade to Cacti version 1.2.31 or later.
What problem does CVE-2026-40941 present?
CVE-2026-40941 allows a package import signature validation bypass, which can permit self-signed packages.
Which versions of Cacti are affected by CVE-2026-40941?
Cacti versions 1.2.30 and prior are affected by CVE-2026-40941.
What is the impact of CVE-2026-40941?
The impact of CVE-2026-40941 includes potential unauthorized installation of self-signed packages in Cacti.