CVE-2025-26520
CVSS 3.1 Score 7.6 of 10 (high)
Details
Summary
CVE-2025-26520 is a new SQL injection vulnerability affecting Cacti up to version 1.2.29. This issue resides in the template function of host_templates.php and can be exploited through the graph_template parameter. Notably, this vulnerability stems from an incomplete remediation of the prior SQL injection flaw, CVE-2024-54146. Attackers can manipulate input to inject malicious SQL commands and potentially gain unauthorized access to sensitive data or modify configurations. System administrators are advised to upgrade to a patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cacti
Affected Vendors
- Cacti