CVE-2026-39938 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-39938 requires immediate attention.
· 7 min read
Executive Summary
CVE-2026-39938 is a critical vulnerability in Cacti with a CVSS 9.8 score. Versions 1.2.30 and earlier are affected by an unauthenticated local file inclusion (LFI) issue tied to graph_theme and hardening around rrdtool IPC serialization. In practical terms, an attacker may be able to read sensitive files from the server without logging in, which can expose configuration secrets, credentials, and internal system data.
This issue is fixed in Cacti 1.2.31. Even though there is no current KEV listing and no confirmed exploitation in the wild, the severity is high enough that solo developers and small teams should treat this as an urgent patch-and-verify event.
Immediate Action
- Upgrade Cacti to 1.2.31 immediately. If you cannot patch today, isolate the service from the public internet and restrict access to trusted IPs only.
- Disable or restrict any exposed Cacti admin or graphing endpoints until the upgrade is complete, especially if the instance is reachable over the internet.
- Rotate secrets that may be stored in Cacti config files or adjacent application files, including database passwords and API keys.
- Review logs for unusual requests involving
graph_theme, file path traversal, or unexpected access to local files. - Back up the current instance before patching, then test the upgrade in a staging clone if you have one.
- Vendor advisory: TODO: insert official Cacti advisory link
Affected Versions
cacti@<=1.2.30vulnerablecacti@1.2.31fixedcacti@>=1.2.31safe, assuming no local backports or custom patches reintroduced the issue
Resolution Guide
Best fix: upgrade Cacti to 1.2.31 or later using your normal deployment method.
# Generic package/source deployment
# TODO: replace with your environment's install path or package name
git fetch --tags
git checkout v1.2.31
# then rebuild/redeploy according to your setup
# Docker: pin to a fixed safe tag if available
docker pull TODO_CACTI_IMAGE:1.2.31
docker stop cacti
docker rm cacti
docker run -d --name cacti TODO_CACTI_IMAGE:1.2.31
# apt/yum example for systems that package Cacti
sudo apt update
sudo apt install --only-upgrade cacti
# or, if your repo has a fixed build:
sudo apt install cacti=1.2.31-1
# yum/dnf example
sudo dnf upgrade cacti
# or:
sudo yum update cacti
JavaScript / Python / Java ecosystems: Cacti is not typically installed through npm, pip, pipx, Maven, or Gradle. If your team wraps Cacti in automation, scripts, or container tooling, update the wrapper dependencies separately, but the vulnerable component itself must be patched at the Cacti deployment layer.
# npm/yarn/pnpm wrapper example only
npm audit
yarn audit
pnpm audit
# then update any deployment scripts that pin old Cacti images or URLs
# pip/pipx wrapper example only
pip list --outdated
pipx list
# update any automation that downloads or deploys Cacti 1.2.30 or earlier
# Maven/Gradle wrapper example only
mvn -q dependency:tree
./gradlew dependencies
# check for build scripts that reference vulnerable Cacti artifacts or images
Config hardening: until patched, reduce exposure by limiting network access and disabling public access to the web UI if possible.
# Example reverse proxy restriction
location / {
allow 10.0.0.0/8;
allow 192.168.0.0/16;
deny all;
}
# Example: isolate the service at the host firewall
sudo ufw allow from 10.0.0.0/8 to any port 80
sudo ufw allow from 10.0.0.0/8 to any port 443
sudo ufw deny 80
sudo ufw deny 443
Minimal code/patch guidance: if you maintain a fork, ensure user-controlled theme or file path input cannot reach file include or IPC serialization paths without strict allowlisting.
// Pseudocode: reject unsafe theme input before file access
$allowedThemes = ['default', 'modern', 'classic'];
if (!in_array($graph_theme, $allowedThemes, true)) {
throw new Exception('Invalid theme');
}
Detection & Verification
Check the installed version first. If it is 1.2.30 or lower, treat the instance as vulnerable until proven otherwise.
# Common version checks
cacti --version 2>/dev/null || grep -R "1.2.30\|1.2.29\|1.2.28" /var/www /usr/share 2>/dev/null
# If installed from source, inspect release tags or package metadata
grep -R "VERSION" /var/www/cacti/include /var/www/cacti/lib 2>/dev/null
Look for suspicious request patterns in web logs, especially requests that mention graph_theme, unexpected file paths, or traversal-like sequences.
# Apache/Nginx log triage
grep -R "graph_theme\|../\|%2e%2e%2f\|rrdtool" /var/log/apache2 /var/log/nginx 2>/dev/null
Verify the fix after upgrading:
# Confirm the running version is 1.2.31 or later
grep -R "1.2.31" /var/www/cacti 2>/dev/null
# Re-test access controls and confirm no public exposure
curl -I https://YOUR-CACTI-HOST/
# If you use container images, confirm the tag
docker inspect --format='{{.Config.Image}}' cacti
Dependency and vulnerability scanners: use your normal inventory tool, then confirm the Cacti package or image is no longer pinned to 1.2.30 or earlier. If you maintain IaC, search for old image tags and deployment URLs.
# Search infrastructure code for old pins
grep -R "1.2.30\|cacti:" ./
Risk and Impact
This flaw can let an attacker read files from the Cacti server without authentication. That can expose database credentials, application secrets, configuration files, and potentially other sensitive local data, making follow-on compromise much easier.
For small teams, the blast radius can be large because monitoring systems often have broad network visibility and privileged credentials. If Cacti shares secrets with other services, a single exposed instance can become a pivot point into the rest of your environment.