OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-83621

HIGH · CVSS 8.1 EPSS 0.53% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The ntopng web-based network traffic monitoring application prior to version 6.7.260717 is vulnerable due to a lack of proper administrator checks in the edit_blacklist.lua script, allowing any authenticated user to manipulate critical parameters. This vulnerability enables non-admin users to redirect threat-intelligence downloads, disable blocklists, or disrupt scheduled updates, compromising the integrity and availability of the monitoring system. Organizations using ntopng should prioritize upgrading to version 6.7.260717 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-83621
Severity
HIGH
CVSS
8.1
EPSS
0.53%

Original NVD Description

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList for any authenticated user. The list_name, list_enabled, url, and list_update parameters allow a non-admin user to redirect threat-intelligence downloads to attacker-controlled content, disable blocklists, or prevent scheduled updates. The changes are persisted through Redis and reloaded without a lower-level authorization guard, undermining the integrity and availability of ntopng's threat-intelligence monitoring. This issue is fixed in version 6.7.260717.