Back

HIGH

Cacti graph_view.php RCE via graph_start Parameter Injection

Published Aug 30, 2025

Description

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 30, 2025
Updated Jul 28, 2026
Reserved Aug 28, 2025
CISA Vulnrichment
Updated Sep 2, 2025
NVD
Status Analyzed
Modified Sep 23, 2026
Red Hat
Severity n/a
Public date n/a