Skip to main content

CVE-2026-82412: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in ntop ntopng

0
High
VulnerabilityCVE-2026-82412cvecve-2026-82412cwe-78
Published: 09/21/2026 (09/21/2026, 15:56:26 UTC)
Source: CVE Database V5
Vendor/Project: ntop
Product: ntopng

Description

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the scan_ports parameter without an administrator gate and pass it through validateSingleWord, which permits shell metacharacters. scripts/lua/modules/vulnerability_scan/vs_utils.lua then concatenates scan_ports into an nmap command in nmap_scan_host and executes the command through ntop.execCmd or ntop.execCmdAsync and popen. Any authenticated non-admin user can execute operating-system commands as the ntopng process account when nmap is available. Because the endpoints accept GET requests while ntopng's CSRF validation applies to POST request bodies, an attacker can also trigger the command through a logged-in user's browser without possessing ntopng credentials. This issue is fixed in version 6.7.260717.

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

ntop

ntopng

Affected versions
<6.7.260717
GitHub Actionsmore threats →ai
ntop/ntopng
pkg:github/ntop/ntopng
Affected versions
<6.7.260717

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/21/2026, 16:16:53 UTC

Technical Analysis

ntopng is vulnerable to OS command injection in its vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua prior to version 6.7.260717. The scan_ports parameter is accepted without administrator gate and passed through a validation function that permits shell metacharacters. This parameter is then concatenated into an nmap command executed via ntop.execCmd or ntop.execCmdAsync and popen, enabling command execution as the ntopng process user. The endpoints accept GET requests, and since CSRF validation applies only to POST bodies, an attacker can trigger the command injection through a logged-in user's browser without needing ntopng credentials. The vulnerability is addressed in version 6.7.260717.

Potential Impact

An attacker with authenticated non-administrator access to ntopng can execute arbitrary operating system commands with the privileges of the ntopng process. This can lead to full compromise of the host running ntopng. The vulnerability can also be exploited via CSRF through a logged-in user's browser, increasing the attack surface. The CVSS score of 8.8 indicates high severity with impacts on confidentiality, integrity, and availability.

Mitigation Recommendations

Upgrade ntopng to version 6.7.260717 or later, where this vulnerability is fixed. Until upgraded, restrict access to the vulnerable endpoints to trusted administrators only and consider disabling the vulnerability scan feature if feasible. Note that the vulnerability can be exploited via GET requests bypassing CSRF protections, so additional network-level controls may be necessary to mitigate risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-08-28T22:00:43.514Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ab1551555bf5e2cf51ebf0d

Added to database: 09/21/2026, 16:02:29 UTC

Last enriched: 09/21/2026, 16:16:53 UTC

Last updated: 09/22/2026, 00:06:33 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses