CVE-2025-26520

CRITICAL

Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists because of an incomplete fix for CVE-2024-54146.

Affects 1 product across 1 vendor.

BCS6.29
CVSS 3.19.8
EPSS0.5%
Percentile39th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-89: SQL Injection

Attacker inserts SQL commands into application queries through user-controlled input, allowing unauthorized database access.

Related Attack Patterns (CAPEC)
CAPEC-7 Blind SQL Injection
via CWE-89
CAPEC-108 Command Line Execution through SQL Injection
via CWE-89
CAPEC-109 Object Relational Mapping Injection
via CWE-89
CAPEC-110 SQL Injection through SOAP Parameter Tampering
via CWE-89
CAPEC-470 Expanding Control over the Operating System from the Database
via CWE-89
Show all 6
via CWE-89

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

Cacti through version 1.2.29 is vulnerable to SQL injection in the template function within host_templates.php due to an incomplete fix for CVE-2024-54146. This vulnerability could allow an attacker to execute arbitrary SQL commands, potentially leading to unauthorized data access, modification, or deletion.

BSID: BS-2025-GLOBAL-042820-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-26520?
Cacti through version 1.2.29 is vulnerable to SQL injection in the template function within host_templates.php due to an incomplete fix for CVE-2024-54146. This vulnerability could allow an attacker to execute arbitrary SQL commands, potentially leading to unauthorized data access, modification, or deletion.
What is the CVSS score for CVE-2025-26520?
CVE-2025-26520 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.5%.
Is CVE-2025-26520 actively exploited?
No confirmed active exploitation of CVE-2025-26520 as of 2026-05-30.
How do I remediate CVE-2025-26520?
Priority: IMMEDIATE. Advisory: https://github.com/Cacti/cacti/commit/7fa60c03ad4a69c701ac6b77c85a8927df7acd51
What systems are affected by CVE-2025-26520?
CVE-2025-26520 affects: Cacti.
Vulnerability Details
CVE IDCVE-2025-26520
BSIDBS-2025-GLOBAL-042820-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2025-02-12
Last Modified2025-03-03
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists because of an incomplete fix for CVE-2024-54146.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The attack vector involves sending a maliciously crafted request to the host_templates.php script with a specially designed graph_template parameter. This parameter is not properly sanitized, allowing SQL injection to occur.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cacti Cacti
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 551 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash015e166332104174e2912026084416e179db72cc4fe08b97f87273803e5875316fe3d90f323a146845e8c29ecb0f1e980cb75c4fc536508d40adf68c688ab17d
Related CVEs affecting Cacti
CVE-2024-29895 10.0 Cacti provides an operational monitoring and fault management framework. A co... CVE-2022-46169 9.8 Cacti is an open source platform which provides a robust and extensible opera... CVE-2022-0730 9.8 Under certain ldap conditions, Cacti authentication can be bypassed with cert... CVE-2017-12065 9.8 spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute ... CVE-2023-39361 9.8 Cacti is an open source operational monitoring and fault management framework...
View all Cacti CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →