PatchSiren cyber security CVE debrief
CVE-2026-40084 Cacti CVE debrief
CVE-2026-40084 is a Path Traversal vulnerability in Cacti, a popular open-source performance and fault management framework. The vulnerability affects versions 1.2.30 and prior, allowing attackers to read arbitrary files from the filesystem. This is achieved through a two-stage process: first, an attacker injects a malicious file format into the database, and then, the application reads the file without proper validation. The issue has been fixed in version 1.2.31. Users of affected versions should update to the latest version to mitigate this vulnerability.
- Vendor
- Cacti
- Product
- Unknown
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-25
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-06-25
- Advisory updated
- 2026-06-29
Who should care
System administrators and security teams responsible for Cacti installations should be aware of this vulnerability. Given the medium CVSS score of 6.5, this vulnerability may not be considered critical, but it still poses a risk, especially in environments where an attacker has legitimate access to the system. Updating to version 1.2.31 or later is recommended.
Technical summary
The vulnerability occurs in two stages. First, in lib/html_reports.php at line 283, $save['format_file'] = $post['format_file'] is stored directly into the database without validation. Then, in lib/reports.php at line 667, CACTI_PATH_FORMATS . '/' . $format_file is concatenated, and line 670 calls file($format_file), allowing for arbitrary file reads. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating a medium severity vulnerability.
Defensive priority
Medium priority should be given to updating Cacti installations to version 1.2.31 or later. While the CVSS score is medium, the vulnerability's impact on confidentiality is high, making it important to address.
Recommended defensive actions
- Update Cacti to version 1.2.31 or later
- Review and validate user input for file formats
- Monitor for suspicious file access patterns
- Implement additional security measures to restrict file system access
- Conduct regular security audits and vulnerability assessments
Evidence notes
The CVE record and NVD detail provide comprehensive information about the vulnerability. The CVE was published on 2026-06-25 and modified on 2026-06-29. The vulnerability has been analyzed and has a CWE-22 classification.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-40084 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-40084
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-40084 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40084
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/Cacti/cacti/commit/4c09efaebf3a9faec66969d0b5c4aceaf397f37f
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/Cacti/cacti/security/advisories/GHSA-mjvw-mhj5-9jcj
[email protected] - Exploit, Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.