CVE-2014-2709: Cacti

High severity, CVSS 7.5. EPSS: 5.1% chance of exploitation in the next 30 days.

lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified parameters.

Affected products

  • Cacti Cacti: from 0.8.7, up to and including 0.8.7g; from 0.8.8, up to and including 0.8.8b
  • Debian Debian Linux: version 7.0 only; version 8.0 only

Published 2014-04-23. Last modified 2026-06-17.