Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages
Published Jun 25, 2026
7.1
HIGHCVSS 4.0
EPSS 0.27%
Description
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.
Affected products
-
- Version < 1.2.31StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This is an Important flaw in Cacti where a package import signature validation bypass allows the installation of self-signed packages. This could lead to the execution of arbitrary code with the privileges of the Cacti application, potentially compromising the integrity and availability of the system. Exploitation requires an attacker to have privileges to import packages.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-40941 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2493265 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39589 Advisory
- https://github.com/Cacti/cacti/pull/7054 x_refsource_MISCIssue TrackingPatch
- https://github.com/Cacti/cacti/releases/tag/release%2F1.2.31 x_refsource_MISCProductRelease Notes
- https://github.com/Cacti/cacti/security/advisories/GHSA-274c-97hj-pv2v x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40941
- https://www.cve.org/CVERecord?id=CVE-2026-40941
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-40941 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2493265 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39589 | Advisory | |
| https://github.com/Cacti/cacti/pull/7054 | x_refsource_MISCIssue TrackingPatch | |
| https://github.com/Cacti/cacti/releases/tag/release%2F1.2.31 | x_refsource_MISCProductRelease Notes | |
| https://github.com/Cacti/cacti/security/advisories/GHSA-274c-97hj-pv2v | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-40941 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-40941 |
Change history (0)
No recorded changes yet.