๐Ÿ” CVE Alert

CVE-2026-82412

HIGH 8.8

ntopng: Remote Code Execution via OS Command Injection in Vulnerability-Scan REST API

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the scan_ports parameter without an administrator gate and pass it through validateSingleWord, which permits shell metacharacters. scripts/lua/modules/vulnerability_scan/vs_utils.lua then concatenates scan_ports into an nmap command in nmap_scan_host and executes the command through ntop.execCmd or ntop.execCmdAsync and popen. Any authenticated non-admin user can execute operating-system commands as the ntopng process account when nmap is available. Because the endpoints accept GET requests while ntopng's CSRF validation applies to POST request bodies, an attacker can also trigger the command through a logged-in user's browser without possessing ntopng credentials. This issue is fixed in version 6.7.260717.

CWE CWE-78
Vendor ntop
Product ntopng
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for ntop ntopng

Be the first to know when new high vulnerabilities affecting ntop ntopng are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

ntop / ntopng
< 6.7.260717

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ntop/ntopng/security/advisories/GHSA-2c6p-4pfj-qv58 github.com: https://github.com/ntop/ntopng/commit/0d3156274f4d12db8b61432ebeded10966c01f3e github.com: https://github.com/ntop/ntopng/commit/771b34a9d37f5de989eec4f2f8f2e852db1c7e5e github.com: https://github.com/ntop/ntopng/commit/838ccd523a3d4a71b29a62f7653e572a1ffa5cf6 github.com: https://github.com/ntop/ntopng/commit/9f42a12251d881e3a20ebd667c1a2e6a6570c270