What is CVE-2026-71287?
CVE-2026-71287 is a vulnerability in the Cacti monitoring tool. The weak regex in the `sanitize_sql_column()` function fails to properly sanitize user-supplied ORDER BY column names, potentially allowing SQL injection attacks. Affected users should immediately update Cacti to the latest version and monitor for suspicious inputs.
Azərbaycanca: CVE-2026-71287, Cacti monitorinq alətində aşkar edilmiş boşluqdur. `sanitize_sql_column()` funksiyasındakı zəif regex istifadəçi tərəfindən təmin edilən ORDER BY sütun adlarını düzgün təmizləmədiyi üçün SQL injection hücumlarına yol aça bilər. Təsirlənən istifadəçilər dərhal Cacti-ni ən son versiyaya yeniləməli və şübhəli girişləri izləməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Does this vulnerability (CVE-2026-71287) in Cacti lead to full system compromise?
While full system compromise is not explicitly stated in the context, the vulnerability allows SQL injection attacks via the ORDER BY clause, which could potentially lead to reading, modifying, or deleting information in the database. Affected users are urged to apply the patch immediately.
Is there a temporary workaround for CVE-2026-71287?
The provided information only recommends updating Cacti to the latest version and monitoring for suspicious inputs. No temporary workarounds such as bypasses or specific WAF rules are mentioned.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.