Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-39949 — Cacti ≤ 1.2.30 Auth RCE - Host variable injection | Kitploit
Tools/GitHubGitHub/lukehebe/cve-2026-39949
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and Control
GitHublukehebe/cve-2026-39949

CVE-2026-39949

Cacti ≤ 1.2.30 Auth RCE - Host variable injection

View Repository
73 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-39949: Authenticated Remote Code Execution in Cacti Through Host Variable Injection

Summary

An OS command injection vulnerability in Cacti ≤ 1.2.30 allows any authenticated user with device and graph template creation privileges to execute arbitrary commands on the underlying server. The flaw exists because user-controlled host metadata fields (specifically the device notes field) are substituted into RRDtool command-line arguments via Cacti’s variable replacement engine without any sanitization or escaping. An attacker can inject shell metacharacters into the notes field, craft a graph template that references the |host_notes| variable, and trigger graph rendering to achieve full remote code execution as the web server user.

Usage:

python3 cacti_rce_poc.py --url http://target/cacti --user admin --pass admin --cmd 'id'

OOB command execution:

python3 cacti_rce_poc.py --url http://target/cacti --user admin --pass admin --oob your.oastify.com
image image image
Download Tool