CVE-2026-71287

NameCVE-2026-71287
DescriptionCacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and table.column), a payload such as passes through completely unmodified.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cacti (PTS)bookworm, bookworm (security)1.2.24+ds1-1+deb12u5undetermined
trixie1.2.30+ds1-1undetermined
forky, sid1.2.31+ds1-3undetermined

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cactisource(unstable)undetermined

Notes

check, assigned from "Turan Security" CNA without further detailed references

Search for package or bug name: Reporting problems