CVE-2026-71287

NameCVE-2026-71287
DescriptionCacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and table.column), a payload such as passes through completely unmodified.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cacti (PTS)bullseye1.2.16+ds1-2+deb11u3undetermined
bullseye (security)1.2.16+ds1-2+deb11u5undetermined
bookworm, bookworm (security)1.2.24+ds1-1+deb12u5undetermined
trixie1.2.30+ds1-1undetermined
forky, sid1.2.31+ds1-2undetermined

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cactisource(unstable)undetermined

Notes

check, assigned from "Turan Security" CNA without further detailed references

Search for package or bug name: Reporting problems