Unauthorized Access in ntopng Network Monitoring Application
CVE-2026-83621
What is CVE-2026-83621?
ntopng, a web-based network traffic monitoring tool, is susceptible to an improper access control vulnerability. In versions prior to 6.7.260717, the application allows any authenticated user to modify critical threat-intelligence settings without proper administrative verification. The lack of authorization checks on the /lua/rest/v2/edit/system/edit_blacklist.lua endpoint enables non-admin users to manipulate blacklist configurations, potentially redirecting downloadable threat intelligence to malicious sources, disabling protective blocklists, or interfering with scheduled updates. These unauthorized changes are stored and reapplied from Redis without sufficient oversight, threatening the integrity and availability of ntopng's monitoring capabilities.
Affected Version(s)
ntopng < 6.7.260717
