CVE-2026-40083 | Cacti up to 1.2.30 managers.php cacti_unserialize selected_items sql injection (GHSA-j9jv-6xjq-9hhj)
A vulnerability described as critical has been identified in Cacti up to 1.2.30. Affected by this issue is the function cacti_unserialize of the file managers.php. Such manipulation of the argument selected_items leads to sql injection.
This vulnerability is listed as CVE-2026-40083. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.