CVE-2026-82412: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in ntop ntopng
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the scan_ports parameter without an administrator gate and pass it through validateSingleWord, which permits shell metacharacters. scripts/lua/modules/vulnerability_scan/vs_utils.lua then concatenates scan_ports into an nmap command in nmap_scan_host and executes the command through ntop.execCmd or ntop.execCmdAsync and popen. Any authenticated non-admin user can execute operating-system commands as the ntopng process account when nmap is available. Because the endpoints accept GET requests while ntopng's CSRF validation applies to POST request bodies, an attacker can also trigger the command through a logged-in user's browser without possessing ntopng credentials. This issue is fixed in version 6.7.260717.
AI Analysis
Technical Summary
ntopng is vulnerable to OS command injection in its vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua prior to version 6.7.260717. The scan_ports parameter is accepted without administrator gate and passed through a validation function that permits shell metacharacters. This parameter is then concatenated into an nmap command executed via ntop.execCmd or ntop.execCmdAsync and popen, enabling command execution as the ntopng process user. The endpoints accept GET requests, and since CSRF validation applies only to POST bodies, an attacker can trigger the command injection through a logged-in user's browser without needing ntopng credentials. The vulnerability is addressed in version 6.7.260717.
Potential Impact
An attacker with authenticated non-administrator access to ntopng can execute arbitrary operating system commands with the privileges of the ntopng process. This can lead to full compromise of the host running ntopng. The vulnerability can also be exploited via CSRF through a logged-in user's browser, increasing the attack surface. The CVSS score of 8.8 indicates high severity with impacts on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade ntopng to version 6.7.260717 or later, where this vulnerability is fixed. Until upgraded, restrict access to the vulnerable endpoints to trusted administrators only and consider disabling the vulnerability scan feature if feasible. Note that the vulnerability can be exploited via GET requests bypassing CSRF protections, so additional network-level controls may be necessary to mitigate risk.
CVE-2026-82412: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in ntop ntopng
Description
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the scan_ports parameter without an administrator gate and pass it through validateSingleWord, which permits shell metacharacters. scripts/lua/modules/vulnerability_scan/vs_utils.lua then concatenates scan_ports into an nmap command in nmap_scan_host and executes the command through ntop.execCmd or ntop.execCmdAsync and popen. Any authenticated non-admin user can execute operating-system commands as the ntopng process account when nmap is available. Because the endpoints accept GET requests while ntopng's CSRF validation applies to POST request bodies, an attacker can also trigger the command through a logged-in user's browser without possessing ntopng credentials. This issue is fixed in version 6.7.260717.
CVSS v3.1
Score 8.8high
Affected software
ntop
ntopng
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ntopng is vulnerable to OS command injection in its vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua prior to version 6.7.260717. The scan_ports parameter is accepted without administrator gate and passed through a validation function that permits shell metacharacters. This parameter is then concatenated into an nmap command executed via ntop.execCmd or ntop.execCmdAsync and popen, enabling command execution as the ntopng process user. The endpoints accept GET requests, and since CSRF validation applies only to POST bodies, an attacker can trigger the command injection through a logged-in user's browser without needing ntopng credentials. The vulnerability is addressed in version 6.7.260717.
Potential Impact
An attacker with authenticated non-administrator access to ntopng can execute arbitrary operating system commands with the privileges of the ntopng process. This can lead to full compromise of the host running ntopng. The vulnerability can also be exploited via CSRF through a logged-in user's browser, increasing the attack surface. The CVSS score of 8.8 indicates high severity with impacts on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade ntopng to version 6.7.260717 or later, where this vulnerability is fixed. Until upgraded, restrict access to the vulnerable endpoints to trusted administrators only and consider disabling the vulnerability scan feature if feasible. Note that the vulnerability can be exploited via GET requests bypassing CSRF protections, so additional network-level controls may be necessary to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-28T22:00:43.514Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab1551555bf5e2cf51ebf0d
Added to database: 09/21/2026, 16:02:29 UTC
Last enriched: 09/21/2026, 16:16:53 UTC
Last updated: 09/22/2026, 00:06:33 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.