← Vulnerability feed

Vulnerability record · CVE-2025-24367 · published 27 January 2025

CVE-2025-24367: Cacti graph/template feature allows authenticated PHP file write and RCE

Cacti · Cacti

Cacti lets an authenticated user abuse graph creation and graph template functionality to write arbitrary PHP scripts into the application web root. Because the written files are executable PHP in a web-accessible directory, this turns a low-privilege authenticated account into server-side code execution. The flaw is fixed in Cacti 1.2.29.

8.7 CVSS 4.0 High EPSS 54% · top 1.0% CWE-144 · CWE-144
8.7CVSS 4.0 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityAuthenticated remote code execution with a high EPSS score and public exploit detail, though it requires a valid account and is not in KEV.

What it is

Cacti lets an authenticated user abuse graph creation and graph template functionality to write arbitrary PHP scripts into the application web root. Because the written files are executable PHP in a web-accessible directory, this turns a low-privilege authenticated account into server-side code execution. The flaw is fixed in Cacti 1.2.29.

Impact

An attacker with a valid Cacti account gains remote code execution on the server, allowing full compromise of the Cacti host and any data or credentials it can reach.

Attack surface

Reached over the network through the Cacti web interface; the CVSS 4.0 vector shows network attack, low complexity, and low privileges required, with no user interaction. Authentication is required, so the attacker needs at least one valid Cacti account.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.54024, ~98.95th percentile) and the vendor advisory is tagged Exploit, indicating public exploit detail exists. No ransomware group use is documented.

What to do

  • Upgrade Cacti to 1.2.29 or later, which contains the fix.
  • Restrict and audit Cacti accounts; remove or disable unused accounts and avoid granting graph/template editing rights broadly.
  • Ensure the Cacti web root is not writable by the web server process where feasible, and monitor for unexpected PHP files there.
  • Apply the Debian LTS update if running the packaged version on Debian.
  • Place Cacti behind authentication and network restrictions so it is not exposed to untrusted networks.

Detection

  • Monitor the Cacti web root for newly created or modified .php files and alert on unexpected writes.
  • Review web server logs for requests to Cacti graph/template endpoints followed by access to newly created PHP files.
  • Audit Cacti user activity and logs for graph or graph template creation by accounts that do not normally use those features.
  • Watch for outbound connections or child processes spawned by the web server that indicate code execution.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-24367 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-46169Cacti remote_agent.php auth bypass leads to OS command injectionCacti's remote_agent.php trusts attacker-controlled HTTP headers when resolving the client IP, letting an unauthenticated attacker spoof the poller h…KEVEPSS 100%analysed9.8CVE-2026-39938Cacti path traversal vulnerabilityCacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtoo…EPSS 0.69%9.8CVE-2026-39955Cacti sql injection vulnerabilityCacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FI…EPSS 0.59%9.8CVE-2026-39893Cacti sql injection vulnerabilityCacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into …EPSS 0.67%9.8CVE-2025-26520Cacti sql injection vulnerabilityCacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists be…EPSS 0.48%9.8CVE-2023-39361Cacti graph_view.php SQL injection allows unauthenticated guest accessCacti's graph_view.php is vulnerable to SQL injection. Guest users can reach graph_view.php without authentication by default, so when guest access i…EPSS 89%analysed9.8CVE-2022-0730Cacti improper authentication vulnerabilityUnder certain ldap conditions, Cacti authentication can be bypassed with certain credential types.EPSS 3.5%9.8CVE-2017-12065Cacti vulnerabilityspikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.EPSS 2.9%

Source: NIST National Vulnerability Database (record CVE-2025-24367), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.