OS Command Injection Affecting cacti package, versions <1.2.31-0


Severity

Recommended
0.0
critical
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
1.14% (64th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ALPINE324-CACTI-17373628
  • published18 Jun 2026
  • disclosed25 Jun 2026

Introduced: 18 Jun 2026

CVE-2026-40079  (opens in a new tab)
CWE-78  (opens in a new tab)
CWE-88  (opens in a new tab)

How to fix?

Upgrade Alpine:3.24 cacti to version 1.2.31-0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream cacti package and not the cacti package as distributed by Alpine. See How to fix? for Alpine:3.24 relevant fixed versions and status.

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The escape_command() function at lib/rrd.php is a no-op: it returns $command unchanged. The command line built by rrdtool_function_graph() is passed through this function and then to shell_exec($full_commandline). The risk is in __rrd_execute() where text_format values from graph templates (which may contain host variable substitutions) reach shell_exec without adequate escaping. This issue has been addressed in version 1.2.31.

CVSS Base Scores

version 3.1