PT-2026-104830 · Azure Linux · Ntopng
Published
2026-09-21
·
Updated
2026-09-21
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list available backups.lua and scripts/lua/rest/v2/get/system/configurations/download backup.lua allow any authenticated non-admin user to list and download system-configuration backups without an administrator check. The download path reaches backup config.export backup, and prefs dump utils.build prefs dump table includes the ntopng.user.* Redis key space in the backup. A downloaded backup can therefore disclose password hashes for local users and, when configured, API tokens, TOTP secrets, and WebAuthn credential data, enabling account compromise through usable or recoverable credentials. This issue is fixed in version 6.7.260718.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ntopng