Back

HIGH

Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages

Published Jun 25, 2026

Description

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.

Affected products

Remediation

Red Hat statement

This is an Important flaw in Cacti where a package import signature validation bypass allows the installation of self-signed packages. This could lead to the execution of arbitrary code with the privileges of the Cacti application, potentially compromising the integrity and availability of the system. Exploitation requires an attacker to have privileges to import packages.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 25, 2026
Updated Jun 26, 2026
Reserved Apr 15, 2026
CISA Vulnrichment
Updated Jun 26, 2026
NVD
Status Analyzed
Modified Jun 29, 2026
Red Hat
Severity Important
Public date Jun 25, 2026
ENISA EUVD
Assigner GitHub_M
Published Jun 25, 2026
Updated Jun 26, 2026
Exploited since n/a
EUVD-2026-39589