CVE-2023-39361
CVSS v3
9.8
CRITICAL
EPSS Score
88.8 %
exploit probability, as of 2026-10-05
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Technical details
- Published
- 2023-09-05
Frequently asked questions
What is CVE-2023-39361?
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Is CVE-2023-39361 actively exploited?
Active exploitation of CVE-2023-39361 has not been confirmed. Its EPSS score was 88.8% on 2026-10-05, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2023-39361?
CVE-2023-39361 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2023-39361 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 50 free checks/month · Free API key
Other 2023 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).