Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/kx00007/cve-2026-39902
Vulnerability AnalysisCode AnalysisExploitationWeb SecurityPenetration Testing
GitHubkx00007/cve-2026-39902

CVE-2026-39902

Proof-of-concept exploit for authenticated OS command injection (CWE-78) in Cacti ≤1.2.30, achieving remote code execution with CVSS 7.2.

View Repository
191 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Vulnerability Report: Authenticated RCE Data Input

Researcher: K  |  Product: Cacti ≤ 1.2.30


[01] Vulnerability Summary

FieldValue
ProductCacti — Complete RRDtool-based Graphing Solution
Affected Version(s)≤ 1.2.30
Vulnerability TypeOS Command Injection (CWE-78)
Attack VectorNetwork (authenticated admin)
AuthenticationYes — Administrator account required
Target OSWindows (both vectors) + Linux (direct input_string vector)
CVSSv3.1 Score7.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

[02] Reference

https://github.com/Cacti/cacti/security/advisories/GHSA-c4qp-j9r9-fq24#event-871227

Download Tool