CVE-2026-71287: Cacti

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and table.column), a payload such as passes through completely unmodified.

Affected products

  • Cacti Cacti: up to and including 1.3.0-dev

Published 2026-08-05. Last modified 2026-08-26.