auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade cacti | Mar 31, 2017 | Apr 13, 2016 |
| Freebsd | — | Upgrade cacti | Dec 10, 2025 | Mar 2, 2016 |
| Gentoo Linux | — | Upgrade net-analyzer/cacti. | Oct 30, 2017 | Apr 13, 2016 |
| Suse | — | Upgrade cactiUpgrade cacti-doc | Apr 13, 2016 | Feb 12, 2016 |
| Ubuntu | — | Upgrade cacti | Nov 19, 2024 | Apr 13, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub