CVE-2025-26520

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Feb 12, 2025
CWE ID 89

Summary

CVE-2025-26520 is a new SQL injection vulnerability affecting Cacti up to version 1.2.29. This issue resides in the template function of host_templates.php and can be exploited through the graph_template parameter. Notably, this vulnerability stems from an incomplete remediation of the prior SQL injection flaw, CVE-2024-54146. Attackers can manipulate input to inject malicious SQL commands and potentially gain unauthorized access to sensitive data or modify configurations. System administrators are advised to upgrade to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share