{"id":"CVE-2026-84989","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-84989","summary":"ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua`…","details":"ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and `POST /lua/rest/v2/edit/tag/tag.lua` — perform no authorization check at all. Any authenticated user, including a non-administrator (\"unprivileged\") account, can delete or rename any tag in the system, including tags created by an administrator. Version 6.7.260718 contains a fix.","published":"2026-09-03T15:17:36.680","modified":"2026-09-03T15:17:36.680","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/ntop/ntopng/commit/0e41f24b367fb9caf750459da67827326e3289e8","label":"ntop/ntopng@0e41f24"},"references":[{"type":"WEB","url":"https://github.com/ntop/ntopng/commit/0e41f24b367fb9caf750459da67827326e3289e8"},{"type":"WEB","url":"https://github.com/ntop/ntopng/security/advisories/GHSA-43p9-5758-wwq8"},{"type":"WEB","url":"https://github.com/ntop/ntopng/security/advisories/GHSA-43p9-5758-wwq8"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T15:17:36.680"}}