CVE-2026-82412
ntopng before 6.7.260717: the vulnerability-scan REST endpoints pass a caller-supplied host into the scanner shell, so a request to the monitoring UI runs commands on the appliance (CVSS 8.8)
- Severity
- high
- Affected product
- ntopng
- Affected versions
- ntopng < 6.7.260717
- Fixed in
- ntopng 6.7.260717
- Added to NewScan
- 2026-09-22
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints ntopng from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-22 (/daily-cve). Same fingerprint and same observation source as the CVE-2026-84990 row above. GHSA-2c6p-4pfj-qv58 names scripts/lua/rest/v2/add/host/to_scan.lua and its sibling and states affected as "prior to 6.7.260717". NOT probed actively and that is the point: the proof of a command injection here is running a command on somebody's network-monitoring appliance, which sees every flow on the segment - a version match tells the operator to patch without touching it. The two ntopng rows carry DIFFERENT bounds one day apart (260717 vs 260718); an install on exactly 6.7.260717 is patched for this one and still vulnerable to the backup exposure, which is why the pair cannot be expressed without the fingerprint's three-component capture.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →