Authorization Bypass in ntopng Network Monitoring Application
CVE-2026-84989

7.1HIGH

Key Information:

Vendor

Ntop

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-84989?

A vulnerability has been identified in ntopng, a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, certain REST v2 endpoints responsible for managing tags lack necessary authorization checks. As a result, any authenticated user, including those without administrative privileges, can modify or delete any tag within the system, including those created by administrators. This flaw raises significant security concerns as it compromises the integrity of the tagging system. Version 6.7.260718 has been released to address and remediate this vulnerability.

Affected Version(s)

ntopng >= 6.7.0, < 6.7.260718

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.