CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-40079

Critical · CVSS 9.8

Cacti — OS Command Injection via unsanitized shell_exec in escape_command()

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-78, CWE-88

Description

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The escape_command() function at lib/rrd.php is a no-op: it returns $command unchanged. The command line built by rrdtool_function_graph() is passed through this function and then to shell_exec($full_commandline). The risk is in __rrd_execute() where text_format values from graph templates (which may contain host variable substitutions) reach shell_exec without adequate escaping. This issue has been addressed in version 1.2.31.

Search profile — drives PoC discovery

Symbols escape_commandrrd.phprrdtool_function_graph__rrd_executeshell_execfull_commandlinetext_format
Keywords CVE-2026-40079Cactiescape_commandrrd.phpcommand injectionshell_execrrdtool_function_graph__rrd_executeGHSA-xq98-376r-hv9j
Versions: 1.2.30 and prior (fixed in 1.2.31)

References

Status: enriched · ingested 2026-06-25T18:00:38.000Z · profiled 2026-07-01T06:30:14.000Z