PT-2026-96151 · Ntopng · Ntopng

CVE-2026-82412

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ntopng versions prior to 6.7.260717
Description An issue exists where the endpoints 'scripts/lua/rest/v2/add/host/to scan.lua' and 'scripts/lua/rest/v2/exec/host/schedule vulnerability scan.lua' accept the scan ports parameter without requiring administrator privileges. The parameter is processed by validateSingleWord, which allows shell metacharacters. Subsequently, the nmap scan host function in 'scripts/lua/modules/vulnerability scan/vs utils.lua' concatenates scan ports into an nmap command, which is then executed via ntop.execCmd, ntop.execCmdAsync, or popen. This allows authenticated non-admin users to execute operating-system commands as the ntopng process account if nmap is installed. Additionally, because these endpoints accept GET requests and CSRF validation is only applied to POST request bodies, the command can be triggered through the browser of a logged-in user without needing credentials.
Recommendations Update to version 6.7.260717.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82412
GHSA-2C6P-4PFJ-QV58

Affected Products

Ntopng