When a user is authenticated, Cacti version 1.2.26 is vulnerable to an arbitrary file write vulnerability,
Metasploit
Cacti, version 1.2.22
Last updated 11 months ago
exploit/multi/http/cacti_package_import_rce