๐Ÿ” CVE Alert

CVE-2026-84990

HIGH 8.8

ntopng: Missing Authorization on System Configuration Backup Download and Listing

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any authenticated non-admin user to list and download system-configuration backups without an administrator check. The download path reaches backup_config.export_backup, and prefs_dump_utils.build_prefs_dump_table includes the ntopng.user.* Redis key space in the backup. A downloaded backup can therefore disclose password hashes for local users and, when configured, API tokens, TOTP secrets, and WebAuthn credential data, enabling account compromise through usable or recoverable credentials. This issue is fixed in version 6.7.260718.

CWE CWE-200 CWE-862
Vendor ntop
Product ntopng
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for ntop ntopng

Be the first to know when new high vulnerabilities affecting ntop ntopng are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

ntop / ntopng
< 6.7.260718

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ntop/ntopng/security/advisories/GHSA-7gqc-vjwr-6rh5 github.com: https://github.com/ntop/ntopng/commit/f912ee93bc143330b6ff3bb946ee7211e5ee9e1a