CVE-2020-13230: Cacti

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account (e.g., permission to view logs).

Affected products

  • Cacti Cacti: before 1.2.11 (fixed in 1.2.11)
  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 31 only; version 32 only

Published 2020-05-20. Last modified 2026-06-17.