Cacti disclosed a critical unauthenticated local file inclusion flaw, tracked as CVE-2026-39938 and GHSA-rm7p-qcqm-x5m6, affecting versions up to and including 1.2.30. The issue stems from the graph_theme parameter and can be exploited over the network without privileges or user interaction, earning a CVSS 3.1 score of 9.8. The advisory also notes related hardening for rrdtool IPC serialization, with the weakness associated with path traversal and potential OS command injection concerns.
An earlier security change in the 1.2.x branch sanitized graph_theme with PHP basename() and rejected empty, . and .. values in lib/rrd.php, falling back to the selected theme when input was invalid. Cacti later determined that approach was bypassable and replaced it with stronger filesystem allowlist validation in cacti_validate_theme(). The vendor fixed the vulnerability in 1.2.31, making that release the recommended upgrade target for exposed deployments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
GitHub published security advisory GHSA-rm7p-qcqm-x5m6 for Cacti, tracking CVE-2026-39938 and describing an unauthenticated local file inclusion issue via `graph_theme`. The advisory said the earlier `basename()`-based fix was bypassable and that stronger allowlist validation in `cacti_validate_theme()` was used in the 1.2.31 patch.
A Cacti commit authored by Thomas Vincent implemented a security fix to sanitize the `graph_theme` parameter with `basename()` and reject invalid values to prevent local file inclusion. The change was associated with release 1.2.31 in the `1.2.x` branch.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.