VulnSea

ntopng vulnerabilities

CVEs whose affected-version data names the ntopng package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-83621High· 8.1
today

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.…

Twilightntop · ntopngvia NVD
CVE-2026-84990High· 8.8
today

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any a…

Twilightntop · ntopngvia NVD
CVE-2026-82412High· 8.8
today

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the sca…

Twilightntop · ntopngvia NVD
CVE-2026-86090High· 7.1
2w ago

ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers

ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endp…

Twilightntop · ntopngEPSS 0.25%via NVD
CVE-2026-86091High· 7.1PoC
2w ago

ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings

ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endp…

Midnightntop · ntopngEPSS 0.29%via NVD
ntopng vulnerabilities (CVEs) · VulnSea