In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graphjson.php request with a modified localgraph_id parameter.
{ "urgency": "not yet assigned" }