CVE-2026-39938
Critical · CVSS 9.8Cacti — Local File Inclusion (LFI) and OS Command Injection via graph_theme parameter and rrdtool IPC serialization
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-22, CWE-78
Description
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This issue has been resolved in version 1.2.31.
Search profile — drives PoC discovery
Symbols graph_themerrdtoolIPC serializationgraph_theme LFIrrdtool hardeningGHSA-rm7p-qcqm-x5m69871f0cef9af285398d558c9b3188d5977e01a04
Keywords CVE-2026-39938Cacti LFICacti graph_themeCacti rrdtool IPCCacti unauthenticated LFICacti 1.2.30 exploitCacti path traversalCacti command injectionGHSA-rm7p-qcqm-x5m6 PoCCacti serialization RCE
Versions: 1.2.30 and prior (fixed in 1.2.31)
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-06-25T18:00:38.000Z · profiled 2026-07-01T06:30:14.000Z