CVE-2026-84990
ntopng before 6.7.260718: the system-configuration backup REST endpoints list and hand out configuration backups to a caller that should not be able to read them, exposing the monitoring appliance's stored settings (CVSS 8.8)
- Severity
- high
- Affected product
- ntopng
- Affected versions
- ntopng < 6.7.260718
- Fixed in
- ntopng 6.7.260718
- Added to NewScan
- 2026-09-22
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints ntopng from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-22 (/daily-cve). Version-gated on the tech_signatures "ntopng" header.server row added in the same batch - `Server: ntopng <major>.<minor>.<builddate>` off the login page, measured that day against the vulhub ntopng env (see that row for the full measurement and why the redirect matters). GHSA-7gqc-vjwr-6rh5 names scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and its sibling, and states affected as "prior to 6.7.260718", so the bound is the advisory's own words rather than inferred. VERSION-MATCH ONLY, deliberately: confirming the exposure means actually requesting somebody else's configuration backup off a live monitoring box, which is the read this row exists to warn about, not one to perform. The third component is a build DATE and the fingerprint captures all three for exactly this reason - 6.7.260717 and 6.7.260718 differ only there, and the neighbouring CVE-2026-82412 row turns on that one digit.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →