<Vulnerability name="CVE-2026-40941">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-06-25T23:01:30</PublicDate>
    <Bugzilla id="2493265" url="https://bugzilla.redhat.com/show_bug.cgi?id=2493265" xml:lang="en:us">
cacti: Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>8.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-347</CWE>
    <Details xml:lang="en:us" source="Mitre">
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Cacti, an open-source performance and fault management framework. This vulnerability allows a remote attacker to bypass the package import signature validation. By exploiting this flaw, an attacker can import self-signed packages, potentially leading to the execution of unauthorized code or compromise of system integrity.
    </Details>
    <Statement xml:lang="en:us">
This is an Important flaw in Cacti where a package import signature validation bypass allows the installation of self-signed packages. This could lead to the execution of arbitrary code with the privileges of the Cacti application, potentially compromising the integrity and availability of the system. Exploitation requires an attacker to have privileges to import packages.
    </Statement>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-40941
https://nvd.nist.gov/vuln/detail/CVE-2026-40941
https://github.com/Cacti/cacti/pull/7054
https://github.com/Cacti/cacti/releases/tag/release%2F1.2.31
https://github.com/Cacti/cacti/security/advisories/GHSA-274c-97hj-pv2v
    </References>
</Vulnerability>