๐Ÿ” CVE Alert

CVE-2026-84989

HIGH 7.1

ntopng's Missing Authorization in REST API Allows Non-Admin Users to Delete and Rename Arbitrary Tags

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature โ€” `POST /lua/rest/v2/delete/tag/tag.lua` and `POST /lua/rest/v2/edit/tag/tag.lua` โ€” perform no authorization check at all. Any authenticated user, including a non-administrator ("unprivileged") account, can delete or rename any tag in the system, including tags created by an administrator. Version 6.7.260718 contains a fix.

CWE CWE-862
Vendor ntop
Product ntopng
Published Sep 3, 2026
Last Updated Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for ntop ntopng

Be the first to know when new high vulnerabilities affecting ntop ntopng are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
Low

Affected Versions

ntop / ntopng
>= 6.7.0, < 6.7.260718

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ntop/ntopng/security/advisories/GHSA-43p9-5758-wwq8 github.com: https://github.com/ntop/ntopng/commit/0e41f24b367fb9caf750459da67827326e3289e8