In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graphjson.php request with a modified localgraph_id parameter.