{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/cacti/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2024-25641"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cacti (\u003c 1.2.27)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Cacti"],"content_html":"\u003cp\u003eThe BSI has reported a critical vulnerability in Cacti, a popular network monitoring and graphing tool. The flaw allows a remote, authenticated attacker to execute arbitrary SQL commands through improper input validation within the application. This vulnerability is tracked as CVE-2024-25641. Affected versions include all releases prior to 1.2.27. By successfully injecting malicious SQL queries, an attacker could manipulate database contents, bypass authentication mechanisms, or extract sensitive monitoring data stored within the backend database. This impact is significant for organizations relying on Cacti for network visibility, as it exposes the monitoring infrastructure to administrative compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability enables an attacker to gain unauthorized access to the Cacti database. Given that Cacti often holds credentials for network devices and sensitive configuration data for managed infrastructure, a breach could lead to lateral movement or the compromise of the wider monitored network environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all Cacti installations to version 1.2.27 or later to patch CVE-2024-25641.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for suspicious SQL syntax in requests originating from authenticated users.\u003c/li\u003e\n\u003cli\u003eEnforce strict access control for the Cacti administrative interface to minimize the risk of malicious authenticated users.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T15:20:05Z","date_published":"2026-08-06T15:20:05Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cacti-sql-injection/","summary":"A vulnerability in Cacti versions prior to 1.2.27 allows an authenticated remote attacker to perform SQL injection, potentially leading to unauthorized database access or information disclosure.","title":"SQL Injection Vulnerability in Cacti","url":"https://feed.craftedsignal.io/briefs/2026-08-cacti-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cacti","version":"https://jsonfeed.org/version/1.1"}