CVE-2017-16641: Cacti

High severity, CVSS 7.2. EPSS: 3.2% chance of exploitation in the next 30 days.

lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php.

Affected products

  • Cacti Cacti: version 1.1.27 only

Published 2017-11-07. Last modified 2026-06-17.