CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-39938

Critical · CVSS 9.8

Cacti — Local File Inclusion (LFI) and OS Command Injection via graph_theme parameter and rrdtool IPC serialization

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-22, CWE-78

Description

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This issue has been resolved in version 1.2.31.

Search profile — drives PoC discovery

Symbols graph_themerrdtoolIPC serializationgraph_theme LFIrrdtool hardeningGHSA-rm7p-qcqm-x5m69871f0cef9af285398d558c9b3188d5977e01a04
Keywords CVE-2026-39938Cacti LFICacti graph_themeCacti rrdtool IPCCacti unauthenticated LFICacti 1.2.30 exploitCacti path traversalCacti command injectionGHSA-rm7p-qcqm-x5m6 PoCCacti serialization RCE
Versions: 1.2.30 and prior (fixed in 1.2.31)

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-06-25T18:00:38.000Z · profiled 2026-07-01T06:30:14.000Z