← All CVEs NewScan detects
high

CVE-2026-84990

ntopng before 6.7.260718: the system-configuration backup REST endpoints list and hand out configuration backups to a caller that should not be able to read them, exposing the monitoring appliance's stored settings (CVSS 8.8)

Severity
high
Affected product
ntopng
Affected versions
ntopng < 6.7.260718
Fixed in
ntopng 6.7.260718
Added to NewScan
2026-09-22
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints ntopng from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-22 (/daily-cve). Version-gated on the tech_signatures "ntopng" header.server row added in the same batch - `Server: ntopng <major>.<minor>.<builddate>` off the login page, measured that day against the vulhub ntopng env (see that row for the full measurement and why the redirect matters). GHSA-7gqc-vjwr-6rh5 names scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and its sibling, and states affected as "prior to 6.7.260718", so the bound is the advisory's own words rather than inferred. VERSION-MATCH ONLY, deliberately: confirming the exposure means actually requesting somebody else's configuration backup off a live monitoring box, which is the read this row exists to warn about, not one to perform. The third component is a build DATE and the fingerprint captures all three for exactly this reason - 6.7.260717 and 6.7.260718 differ only there, and the neighbouring CVE-2026-82412 row turns on that one digit.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →