Medium severity4.3NVD Advisory· Published Sep 23, 2019· Updated Jun 17, 2026
CVE-2019-16723
CVE-2019-16723
Description
In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- osv-coords7 versionspkg:rpm/opensuse/cacti&distro=openSUSE%20Tumbleweedpkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/opensuse/cacti&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/cacti-spine&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2012
< 1.2.18-1.2+ 6 more
- (no CPE)range: < 1.2.18-1.2
- (no CPE)range: < 1.2.9-bp151.4.3.1
- (no CPE)range: < 1.2.9-bp151.4.3.1
- (no CPE)range: < 1.2.9-lp151.3.3.1
- (no CPE)range: < 1.2.9-lp151.3.3.1
- (no CPE)range: < 1.2.11-5.1
- (no CPE)range: < 1.2.11-2.1
<=1.2.6+ 1 more
- (no CPE)range: <=1.2.6
- cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*range: <=1.2.6
- Cacti/Cactidescription
Patches
Vulnerability mechanics
References
10- github.com/Cacti/cacti/issues/2964nvdPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZO3ROHHPKLH2JRW7ES5FYSQTWIPNVLQB/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZSCUUCKSYVZLN3PQE7NU76AFWUGT3E2D/nvd
- seclists.org/bugtraq/2020/Jan/25nvd
- security.gentoo.org/glsa/202003-40nvd
- www.debian.org/security/2020/dsa-4604nvd
News mentions
0No linked articles in our index yet.