← Vulnerability feed

Vulnerability record · CVE-2022-46169 · published 5 December 2022

CVE-2022-46169: Cacti remote_agent.php auth bypass leads to OS command injection

Cacti · Cacti

Cacti's remote_agent.php trusts attacker-controlled HTTP headers when resolving the client IP, letting an unauthenticated attacker spoof the poller hostname and pass the authorization check. Once authorized, the polldata action passes the attacker-controlled poller_id into proc_open, enabling OS command injection. It matters because the endpoint is reachable without credentials and the required poller_item action is commonly present via default templates.

9.8 CVSS 3.1 Critical CISA KEV since 16 Feb 2023 EPSS 100% · top 0.1% CWE-74 · InjectionCWE-78 · OS command injection
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides in the `remote_agent.php` file. This file can be accessed without authentication. This function retrieves the IP address of the client via `get_client_addr` and resolves this IP address to the corresponding hostname via `gethostbyaddr`. After this, it is verified that an entry within the `poller` table exists, where the hostname corresponds to the resolved hostname. If such an entry was found, the function returns `true` and the client is authorized. This authorization can be bypassed due to the implementation of the `get_client_addr` function. The function is defined in the file `lib/functions.php` and checks serval `$_SERVER` variables to determine the IP address of the client. The variables beginning with `HTTP_` can be arbitrarily set by an attacker. Since there is a default entry in the `poller` table with the hostname of the server running Cacti, an attacker can bypass the authentication e.g. by providing the header `Forwarded-For: <TARGETIP>`. This way the function `get_client_addr` returns the IP address of the server running Cacti. The following call to `gethostbyaddr` will resolve this IP address to the hostname of the server, which will pass the `poller` hostname check because of the default entry. After the authorization of the `remote_agent.php` file is bypassed, an attacker can trigger different actions. One of these actions is called `polldata`. The called function `poll_for_data` retrieves a few request parameters and loads the corresponding `poller_item` entries from the database. If the `action` of a `poller_item` equals `POLLER_ACTION_SCRIPT_PHP`, the function `proc_open` is used to execute a PHP script. The attacker-controlled parameter `$poller_id` is retrieved via the function `get_nfilter_request_var`, which allows arbitrary strings. This variable is later inserted into the string passed to `proc_open`, which leads to a command injection vulnerability. By e.g. providing the `poller_id=;id` the `id` command is executed. In order to reach the vulnerable call, the attacker must provide a `host_id` and `local_data_id`, where the `action` of the corresponding `poller_item` is set to `POLLER_ACTION_SCRIPT_PHP`. Both of these ids (`host_id` and `local_data_id`) can easily be bruteforced. The only requirement is that a `poller_item` with an `POLLER_ACTION_SCRIPT_PHP` action exists. This is very likely on a productive instance because this action is added by some predefined templates like `Device - Uptime` or `Device - Polling Time`. This command injection vulnerability allows an unauthenticated user to execute arbitrary commands if a `poller_item` with the `action` type `POLLER_ACTION_SCRIPT_PHP` (`2`) is configured. The authorization bypass should be prevented by not allowing an attacker to make `get_client_addr` (file `lib/functions.php`) return an arbitrary IP address. This could be done by not honoring the `HTTP_...` `$_SERVER` variables. If these should be kept for compatibility reasons it should at least be prevented to fake the IP address of the server running Cacti. This vulnerability has been addressed in both the 1.2.x and 1.3.x release branches with `1.2.23` being the first release containing the patch.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with a CVSS of 9.8, KEV listing, and near-maximum EPSS probability makes this an urgent patch-first issue.

What it is

Cacti's remote_agent.php trusts attacker-controlled HTTP headers when resolving the client IP, letting an unauthenticated attacker spoof the poller hostname and pass the authorization check. Once authorized, the polldata action passes the attacker-controlled poller_id into proc_open, enabling OS command injection. It matters because the endpoint is reachable without credentials and the required poller_item action is commonly present via default templates.

Impact

An unauthenticated attacker can execute arbitrary commands on the Cacti server, leading to full compromise of the monitoring host and any data or credentials it holds.

Attack surface

Reached over the network via remote_agent.php with no authentication; the attacker supplies a spoofed Forwarded-For header and brute-forceable host_id and local_data_id values. No user interaction is required, but exploitation depends on a poller_item configured with the POLLER_ACTION_SCRIPT_PHP action.

Exploitation

CVE-2022-46169 is listed in CISA KEV (added 2023-02-16) and has an EPSS 30-day probability of 0.99826 (99.96th percentile), indicating active exploitation. Reference tags include Exploit, and no ransomware campaign use is documented.

What to do

  • Upgrade Cacti to 1.2.23 or later (or the corresponding 1.3.x release) to apply the vendor patch.
  • If immediate patching is not possible, restrict access to remote_agent.php to trusted poller IPs at the network or web server layer.
  • Review and remove or restrict poller_item entries using the POLLER_ACTION_SCRIPT_PHP action where not required.
  • Do not rely on client-supplied HTTP_ headers for authorization decisions; validate the patch addresses get_client_addr behavior.
  • Monitor Cacti hosts for unexpected outbound connections or child processes spawned by the web server.

Detection

  • Inspect web server logs for requests to remote_agent.php with unusual Forwarded-For, X-Forwarded-For, or Client-IP headers.
  • Alert on remote_agent.php requests containing shell metacharacters (;, |, $(), backticks) in poller_id, host_id, or local_data_id parameters.
  • Monitor for processes spawned by the web server user (e.g., www-data, apache) such as id, whoami, curl, or shells.
  • Correlate remote_agent.php access with subsequent outbound network connections or file writes from the Cacti host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-46169 to the Known Exploited Vulnerabilities catalog on 16 February 2023 as "Cacti Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 9 March 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-46169 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-39938Cacti path traversal vulnerabilityCacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtoo…EPSS 0.69%9.8CVE-2026-39955Cacti sql injection vulnerabilityCacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FI…EPSS 0.59%9.8CVE-2026-39893Cacti sql injection vulnerabilityCacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into …EPSS 0.67%9.8CVE-2025-26520Cacti sql injection vulnerabilityCacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists be…EPSS 0.48%9.8CVE-2023-39361Cacti graph_view.php SQL injection allows unauthenticated guest accessCacti's graph_view.php is vulnerable to SQL injection. Guest users can reach graph_view.php without authentication by default, so when guest access i…EPSS 89%analysed9.8CVE-2022-0730Cacti improper authentication vulnerabilityUnder certain ldap conditions, Cacti authentication can be bypassed with certain credential types.EPSS 3.5%9.8CVE-2017-12065Cacti vulnerabilityspikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.EPSS 2.9%9.3CVE-2026-39948Cacti sql injection vulnerabilityCacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the …EPSS 0.85%

Source: NIST National Vulnerability Database (record CVE-2022-46169), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.