PatchSiren cyber security CVE debrief
CVE-2026-84990 ntop CVE debrief
CVE-2026-84990 is a vulnerability in ntopng, a web-based network traffic monitoring application. Prior to version 6.7.260718, the application allows any authenticated non-admin user to list and download system-configuration backups without proper authorization. This can lead to the disclosure of sensitive information, including password hashes for local users and API tokens, TOTP secrets, and WebAuthn credential data. This issue is fixed in version 6.7.260718.
- Vendor
- ntop
- Product
- ntopng
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for ntopng instances, especially in environments where unauthorized access to system-configuration backups could have significant consequences, should assess exposure and prioritize remediation.
Why it matters
CVE-2026-84990 allows unauthorized access to system-configuration backups in ntopng, potentially disclosing sensitive information. Defenders should prioritize verifying exposure and remediating vulnerable instances.
- Potential disclosure of password hashes for local users
- Potential disclosure of API tokens
- Potential disclosure of TOTP secrets
- Potential disclosure of WebAuthn credential data
Technical summary
The vulnerability exists in scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua, allowing any authenticated non-admin user to list and download system-configuration backups without an administrator check. The download path reaches backup_config.export_backup, and prefs_dump_utils.build_prefs_dump_table includes the ntopng.user.* Redis key space in the backup.
Defensive priority
Defenders should prioritize verifying exposure and remediating vulnerable ntopng instances, especially in environments where unauthorized access to system-configuration backups could have significant consequences.
Recommended defensive actions
- Verify ntopng version and check for exposure
- Remediate vulnerable instances by upgrading to version 6.7.260718 or later
- Review and update access controls for system-configuration backups
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. However, the corpus does not provide explicit information on exploitation or victim impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84990 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84990
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84990 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84990
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ntop/ntopng/commit/f912ee93bc143330b6ff3bb946ee7211e5ee9e1a
-
Source reference
Unverified legacy reference
URL: https://github.com/ntop/ntopng/security/advisories/GHSA-7gqc-vjwr-6rh5
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.