PatchSiren cyber security CVE debrief
CVE-2026-40084 Cacti CVE debrief
CVE-2026-40084 is a Path Traversal vulnerability in Cacti, a popular open-source performance and fault management framework. The vulnerability affects versions 1.2.30 and prior, allowing attackers to read arbitrary files from the filesystem. This is achieved through a two-stage process: first, an attacker injects a malicious file format into the database, and then, the application reads the file without proper validation. The issue has been fixed in version 1.2.31. Users of affected versions should update to the latest version to mitigate this vulnerability.
- Vendor
- Cacti
- Product
- Unknown
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-25
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-06-25
- Advisory updated
- 2026-06-29
Who should care
System administrators and security teams responsible for Cacti installations should be aware of this vulnerability. Given the medium CVSS score of 6.5, this vulnerability may not be considered critical, but it still poses a risk, especially in environments where an attacker has legitimate access to the system. Updating to version 1.2.31 or later is recommended.
Technical summary
The vulnerability occurs in two stages. First, in lib/html_reports.php at line 283, $save['format_file'] = $post['format_file'] is stored directly into the database without validation. Then, in lib/reports.php at line 667, CACTI_PATH_FORMATS . '/' . $format_file is concatenated, and line 670 calls file($format_file), allowing for arbitrary file reads. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating a medium severity vulnerability.
Defensive priority
Medium priority should be given to updating Cacti installations to version 1.2.31 or later. While the CVSS score is medium, the vulnerability's impact on confidentiality is high, making it important to address.
Recommended defensive actions
- Update Cacti to version 1.2.31 or later
- Review and validate user input for file formats
- Monitor for suspicious file access patterns
- Implement additional security measures to restrict file system access
- Conduct regular security audits and vulnerability assessments
Evidence notes
The CVE record and NVD detail provide comprehensive information about the vulnerability. The CVE was published on 2026-06-25 and modified on 2026-06-29. The vulnerability has been analyzed and has a CWE-22 classification.
Official resources
-
CVE-2026-40084 CVE record
CVE.org
-
CVE-2026-40084 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Exploit, Mitigation, Vendor Advisory
This article is AI-assisted and based on the supplied source corpus.