← Vulnerability feed

Vulnerability record · CVE-2023-49084 · published 21 December 2023

CVE-2023-49084: Cacti link.php SQL injection and file path flaw enables remote code execution

Cacti · Cacti

Cacti's link.php combines a detected SQL injection with insufficient processing of an include file path, allowing arbitrary code execution on the server. The flaw requires an authorized user, so it is a post-authentication issue that still yields full server compromise.

8.8 CVSS 3.1 High EPSS 64% · top 0.8% CWE-98 · PHP remote file inclusion
8.8CVSS 3.1 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary code on the server. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the `link.php`. Impact of the vulnerability execution of arbitrary code on the server.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 8.8 with high EPSS and a vendor advisory tagged Exploit, though exploitation requires an authenticated account.

What it is

Cacti's link.php combines a detected SQL injection with insufficient processing of an include file path, allowing arbitrary code execution on the server. The flaw requires an authorized user, so it is a post-authentication issue that still yields full server compromise.

Impact

An authenticated attacker can execute arbitrary code on the Cacti server, leading to full compromise of confidentiality, integrity and availability.

Attack surface

Reached over the network via the link.php component with low attack complexity and no user interaction, but it requires a valid authenticated session (PR:L).

Exploitation

Not listed in CISA KEV, but EPSS is 0.64202 (99.192 percentile) and the vendor advisory is tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the Cacti security fix referenced in vendor advisory GHSA-pfh9-gwm6-86vp and upgrade to a patched release.
  • Apply the Debian LTS and Fedora package updates for Cacti.
  • Restrict Cacti access to trusted networks and enforce least privilege on Cacti accounts.
  • Review and harden PHP include path handling and input validation around link.php.
  • Monitor Cacti accounts for unexpected privilege use or anomalous requests.

Detection

  • Inspect web logs for suspicious requests to link.php containing SQL or path traversal patterns.
  • Monitor for unexpected PHP file creation or modification in Cacti web directories.
  • Alert on outbound connections or process execution spawned by the web server user.
  • Audit Cacti user accounts for unusual login or activity patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-49084 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-46169Cacti remote_agent.php auth bypass leads to OS command injectionCacti's remote_agent.php trusts attacker-controlled HTTP headers when resolving the client IP, letting an unauthenticated attacker spoof the poller h…KEVEPSS 100%analysed9.8CVE-2026-39938Cacti path traversal vulnerabilityCacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtoo…EPSS 0.69%9.8CVE-2026-39955Cacti sql injection vulnerabilityCacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FI…EPSS 0.59%9.8CVE-2026-39893Cacti sql injection vulnerabilityCacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into …EPSS 0.67%9.8CVE-2025-26520Cacti sql injection vulnerabilityCacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists be…EPSS 0.48%9.8CVE-2023-39361Cacti graph_view.php SQL injection allows unauthenticated guest accessCacti's graph_view.php is vulnerable to SQL injection. Guest users can reach graph_view.php without authentication by default, so when guest access i…EPSS 89%analysed9.8CVE-2022-0730Cacti improper authentication vulnerabilityUnder certain ldap conditions, Cacti authentication can be bypassed with certain credential types.EPSS 3.5%9.8CVE-2017-12065Cacti vulnerabilityspikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.EPSS 2.9%

Source: NIST National Vulnerability Database (record CVE-2023-49084), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.