A high-severity blind SQL injection vulnerability tracked as CVE-2026-71287 was disclosed in Cacti, where insufficient sanitization in the sanitize_sql_column() function allows attacker-controlled input to reach raw ORDER BY clauses. The flaw affects multiple pages, including user_log.php, utilities.php, user_domains.php, and user_group_admin.php, through the sort_column GET parameter. Because the regex-based allowlist still permits characters needed for SQL time-delay functions, an authenticated user can trigger time-based blind SQL injection against the Cacti database.
The issue was assigned a CVSS 3.1 score of 8.8 and mapped to CWE-89, with exploitation possible by any authenticated Cacti account regardless of privilege level. Activity in the upstream Cacti GitHub repository shows broader security remediation work around SQL injection and ORDER BY parameter sanitization, alongside other hardening changes, indicating the project is actively addressing input-validation weaknesses and related web application security risks in the codebase.

See affected versions and whether adversaries are exploiting it.
14 events from the most recent confirmed update back to the earliest known activity.
On August 5, 2026, the repository shows several security-related changes, including installer CSRF-token recovery, poller_item cache and Boost RRD staging hardening, support-page CSRF lockout protections, stricter package import signature validation, and refreshed SQL-interpolation baselines. These commits indicate continued remediation and hardening activity after earlier fixes.
A CVE record was published for CVE-2026-71287, describing a high-severity blind SQL injection in Cacti's sanitize_sql_column() handling of ORDER BY input via sort_column. The record states the issue affects versions 0 through 1.3.0-dev and can be exploited remotely by any authenticated user.
Cacti committed a hardening fix for remote-agent forward-confirmed reverse DNS checks and basic authentication identity handling in remote_agent.php. The repository history records this as a distinct security event.
Cacti introduced a security-focused CI change consolidating Semgrep and Psalm taint-analysis gating. This reflects a defensive engineering measure to catch security issues earlier in development.
Cacti issued a security fix to close validator migration regressions across numerous files, including automation, graphing, settings, and user_group_admin.php components. The repository history identifies this as a broad remediation event.
Cacti committed a rendering hardening change to enforce changed-file guardrails. The repository history presents this as part of ongoing security engineering work.
Cacti released a security fix to sanitize ORDER BY sort column and direction on admin list pages, affecting user_domains.php, user_log.php, and utilities.php. This aligns with the later-described blind SQL injection exposure through sort_column handling.
Cacti committed a fix for authentication system bugs. The repository history lists this as a security-relevant change on the same day as other hardening work.
Cacti introduced a hardening change for CSV encoding and process execution handling. The repository history marks this as a security-focused maintenance update.
Cacti committed a security fix described as SQL injection in a cacti endpoint, affecting at least data_debug.php and reports.php. This indicates remediation of a separate SQL injection issue before the later CVE publication.
Cacti added a security-related fix to escape an RRD path in shell execution in spikekill, along with a default method correction. The repository history records this as a hardening event.
Cacti committed a hardening fix for SSRF and SSL verification issues in help.php. The repository history identifies this as a security fix affecting that component.
On March 6, 2026, Cacti changed the API to use get_client_addr() instead of raw REMOTE_ADDR and also unified HTTPS detection with the cacti_is_https() helper. These were security-relevant code changes reflected in the repository history.
Cacti made a hardening change to its Docker development environment. The repository history lists this security-related fix as a distinct 2026 maintenance event.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.