Shell Command Execution Vulnerability in ntopng Network Monitoring Application
CVE-2026-82412
8.8HIGH
What is CVE-2026-82412?
The ntopng application suffers from a command injection vulnerability that allows authenticated non-admin users to execute arbitrary operating system commands on the server. This occurs due to the improper handling of the scan_ports parameter in specific endpoint scripts, which does not validate input and can be manipulated to include shell metacharacters. This vulnerability allows attackers to trigger command execution through crafted GET requests, bypassing typical CSRF protections, and exploit the server's capabilities if nmap is installed. A patch was implemented in version 6.7.260717 to address this issue.
Affected Version(s)
ntopng < 6.7.260717
