OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-82412

HIGH · CVSS 8.8 EPSS 0.65% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The ntopng application is vulnerable due to its handling of the scan_ports parameter in specific vulnerability-scan endpoints, allowing authenticated non-admin users to execute arbitrary operating system commands via crafted requests. This flaw can be exploited remotely, enabling attackers to leverage the privileges of the ntopng process account, posing significant risks to system integrity and confidentiality. Organizations using ntopng versions prior to 6.7.260717 should prioritize patching this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82412
Severity
HIGH
CVSS
8.8
EPSS
0.65%

Original NVD Description

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the scan_ports parameter without an administrator gate and pass it through validateSingleWord, which permits shell metacharacters. scripts/lua/modules/vulnerability_scan/vs_utils.lua then concatenates scan_ports into an nmap command in nmap_scan_host and executes the command through ntop.execCmd or ntop.execCmdAsync and popen. Any authenticated non-admin user can execute operating-system commands as the ntopng process account when nmap is available. Because the endpoints accept GET requests while ntopng's CSRF validation applies to POST request bodies, an attacker can also trigger the command through a logged-in user's browser without possessing ntopng credentials. This issue is fixed in version 6.7.260717.