Vulnerability Description
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflected XSS via tab parameter in the auth_profile.php JavaScript context. This issue has been fixed in version 1.2.31.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cacti | Cacti | < 1.2.31 |
Related Weaknesses (CWE)
References
- https://github.com/Cacti/cacti/commit/891344a5c10b8687a3d2a5d26e6de20f13069e2aPatch
- https://github.com/Cacti/cacti/security/advisories/GHSA-34rf-frc3-v48rPatchVendor Advisory
FAQ
What is CVE-2026-39900?
CVE-2026-39900 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflected XSS via tab parameter in the auth_profile.php JavaScript context. This issue h...
How severe is CVE-2026-39900?
CVE-2026-39900 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-39900?
Check the references section above for vendor advisories and patch information. Affected products include: Cacti Cacti.