Description
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any authenticated non-admin user to list and download system-configuration backups without an administrator check. The download path reaches backup_config.export_backup, and prefs_dump_utils.build_prefs_dump_table includes the ntopng.user.* Redis key space in the backup. A downloaded backup can therefore disclose password hashes for local users and, when configured, API tokens, TOTP secrets, and WebAuthn credential data, enabling account compromise through usable or recoverable credentials. This issue is fixed in version 6.7.260718.
Published: 2026-09-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Credential disclosure and possible account takeover
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in ntopng allows any authenticated user that is not an administrator to list and download system‑configuration backups. The backup files contain sensitive information such as password hashes, API tokens, TOTP secrets, and WebAuthn credentials. Access to these items can enable an attacker to compromise local user accounts and gain wider access within the monitored network, effectively turning a non‑admin presence into a privilege‑escalation vector.

Affected Systems

ntop:ntopng is affected in all releases older than 6.7.260718. The issue resides in the scripts/lua/rest/v2/get/system/configurations list and download endpoints, which were left unprotected. Affected deployments include any installation that has not applied the recent update that fixes the authorization check.

Risk and Exploitability

The CVSS score of 8.8 highlights a high severity. There is no EPSS data, and the vulnerability is not yet listed in the CISA KEV catalog, suggesting that it may not have seen widespread exploitation yet. Nevertheless, the necessary conditions are minimal: an authenticated non‑admin user and network access to the REST API. Once the backup is downloaded, the attacker can analyze the contents offline and leverage the extracted credential material to elevate privileges or compromise additional systems.

Generated by OpenCVE AI on September 21, 2026 at 17:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ntopng to version 6.7.260718 or later to install the fix that enforces administrator checks on backup download and listing.
  • Block or restrict non‑administrator access to the backup‑related REST endpoints (scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and ...download_backup.lua) by adding firewall rules or ACLs.
  • Revoke or limit the privileges of existing non‑admin accounts that should not query backup data, applying the principle of least privilege.

Generated by OpenCVE AI on September 21, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Ntop
Ntop ntopng
Vendors & Products Ntop
Ntop ntopng

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any authenticated non-admin user to list and download system-configuration backups without an administrator check. The download path reaches backup_config.export_backup, and prefs_dump_utils.build_prefs_dump_table includes the ntopng.user.* Redis key space in the backup. A downloaded backup can therefore disclose password hashes for local users and, when configured, API tokens, TOTP secrets, and WebAuthn credential data, enabling account compromise through usable or recoverable credentials. This issue is fixed in version 6.7.260718.
Title ntopng: Missing Authorization on System Configuration Backup Download and Listing
Weaknesses CWE-200
CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-29T15:08:23.975Z

Reserved: 2026-09-02T18:12:13.534Z

Link: CVE-2026-84990

cve-icon Vulnrichment

Updated: 2026-09-29T15:07:57.892Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T17:19:13.340

Modified: 2026-09-29T16:17:12.960

Link: CVE-2026-84990

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T18:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-862

    Missing Authorization