Shell Command Execution Vulnerability in ntopng Network Monitoring Application
CVE-2026-82412

8.8HIGH

Key Information:

Vendor

Ntop

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-82412?

The ntopng application suffers from a command injection vulnerability that allows authenticated non-admin users to execute arbitrary operating system commands on the server. This occurs due to the improper handling of the scan_ports parameter in specific endpoint scripts, which does not validate input and can be manipulated to include shell metacharacters. This vulnerability allows attackers to trigger command execution through crafted GET requests, bypassing typical CSRF protections, and exploit the server's capabilities if nmap is installed. A patch was implemented in version 6.7.260717 to address this issue.

Affected Version(s)

ntopng < 6.7.260717

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.