<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acacticacti/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 06 Aug 2026 15:20:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acacticacti/feed.xml" rel="self" type="application/rss+xml"/><item><title>SQL Injection Vulnerability in Cacti</title><link>https://feed.craftedsignal.io/briefs/2026-08-cacti-sql-injection/</link><pubDate>Thu, 06 Aug 2026 15:20:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-cacti-sql-injection/</guid><description>A vulnerability in Cacti versions prior to 1.2.27 allows an authenticated remote attacker to perform SQL injection, potentially leading to unauthorized database access or information disclosure.</description><content:encoded><![CDATA[<p>The BSI has reported a critical vulnerability in Cacti, a popular network monitoring and graphing tool. The flaw allows a remote, authenticated attacker to execute arbitrary SQL commands through improper input validation within the application. This vulnerability is tracked as CVE-2024-25641. Affected versions include all releases prior to 1.2.27. By successfully injecting malicious SQL queries, an attacker could manipulate database contents, bypass authentication mechanisms, or extract sensitive monitoring data stored within the backend database. This impact is significant for organizations relying on Cacti for network visibility, as it exposes the monitoring infrastructure to administrative compromise.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability enables an attacker to gain unauthorized access to the Cacti database. Given that Cacti often holds credentials for network devices and sensitive configuration data for managed infrastructure, a breach could lead to lateral movement or the compromise of the wider monitored network environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately upgrade all Cacti installations to version 1.2.27 or later to patch CVE-2024-25641.</li>
<li>Audit web server logs for suspicious SQL syntax in requests originating from authenticated users.</li>
<li>Enforce strict access control for the Cacti administrative interface to minimize the risk of malicious authenticated users.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>