CVE-2026-84989 Details
Description
ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and `POST /lua/rest/v2/edit/tag/tag.lua` — perform no authorization check at all. Any authenticated user, including a non-administrator ("unprivileged") account, can delete or rename any tag in the system, including tags created by an administrator. Version 6.7.260718 contains a fix.
A vulnerability exists in ntopng versions 6.7.0 through 6.7.260717, where two REST v2 endpoints for managing tags—'POST /lua/rest/v2/delete/tag/tag.lua' and 'POST /lua/rest/v2/edit/tag/tag.lua'—lack authorization checks. This flaw enables any authenticated user, including those with non-administrator ('unprivileged') accounts, to delete or rename any tag in the system, even those created by administrators. The vulnerability has been patched in version 6.7.260718.
Users should update to ntopng version 6.7.260718 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 3, 2026CISA-ADP
Assessed Sep 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ntop/ntopng/security/advisories/GHSA-43p9-5758-wwq8 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/ntop/ntopng/commit/0e41f24b367fb9caf750459da67827326e3289e8 | [email protected] | Source CodeVendor |
| https://github.com/ntop/ntopng/security/advisories/GHSA-43p9-5758-wwq8 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ntopng | >= 6.7.0, <= 6.7.260717 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | New CVE Received | [email protected] |
| Sep 3, 2026 | CVE Modified | CISA-ADP |
Volerion