Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40941

Опубликовано: 25 июн. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.

A flaw was found in Cacti, an open-source performance and fault management framework. This vulnerability allows a remote attacker to bypass the package import signature validation. By exploiting this flaw, an attacker can import self-signed packages, potentially leading to the execution of unauthorized code or compromise of system integrity.

Отчет

This is an Important flaw in Cacti where a package import signature validation bypass allows the installation of self-signed packages. This could lead to the execution of arbitrary code with the privileges of the Cacti application, potentially compromising the integrity and availability of the system. Exploitation requires an attacker to have privileges to import packages.

Дополнительная информация

Статус:

Important
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2493265cacti: Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages

EPSS

Процентиль: 5%
0.00159
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.

CVSS3: 6.5
nvd
около 1 месяца назад

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.

CVSS3: 6.5
debian
около 1 месяца назад

Cacti is an open source performance and fault management framework. Ve ...

CVSS3: 6.5
fstec
4 месяца назад

Уязвимость программного средства мониторинга сети Cacti, связанная с ошибками проверки криптографической подписи, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 5%
0.00159
Низкий

8.8 High

CVSS3