← All CVEs NewScan detects
high

CVE-2026-82412

ntopng before 6.7.260717: the vulnerability-scan REST endpoints pass a caller-supplied host into the scanner shell, so a request to the monitoring UI runs commands on the appliance (CVSS 8.8)

Severity
high
Affected product
ntopng
Affected versions
ntopng < 6.7.260717
Fixed in
ntopng 6.7.260717
Added to NewScan
2026-09-22
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints ntopng from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-22 (/daily-cve). Same fingerprint and same observation source as the CVE-2026-84990 row above. GHSA-2c6p-4pfj-qv58 names scripts/lua/rest/v2/add/host/to_scan.lua and its sibling and states affected as "prior to 6.7.260717". NOT probed actively and that is the point: the proof of a command injection here is running a command on somebody's network-monitoring appliance, which sees every flow on the segment - a version match tells the operator to patch without touching it. The two ntopng rows carry DIFFERENT bounds one day apart (260717 vs 260718); an install on exactly 6.7.260717 is patched for this one and still vulnerable to the backup exposure, which is why the pair cannot be expressed without the fingerprint's three-component capture.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →