Authorization Bypass in ntopng Network Monitoring Application
CVE-2026-84989
7.1HIGH
What is CVE-2026-84989?
A vulnerability has been identified in ntopng, a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, certain REST v2 endpoints responsible for managing tags lack necessary authorization checks. As a result, any authenticated user, including those without administrative privileges, can modify or delete any tag within the system, including those created by administrators. This flaw raises significant security concerns as it compromises the integrity of the tagging system. Version 6.7.260718 has been released to address and remediate this vulnerability.
Affected Version(s)
ntopng >= 6.7.0, < 6.7.260718
