AZL-103404

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103404.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-103404
Upstream
Published
2026-09-21T17:19:08Z
Modified
2026-09-23T05:36:13Z
Summary
CVE-2026-83621 affecting package ntopng 5.2.1-6
Details

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList for any authenticated user. The list_name, list_enabled, url, and list_update parameters allow a non-admin user to redirect threat-intelligence downloads to attacker-controlled content, disable blocklists, or prevent scheduled updates. The changes are persisted through Redis and reloaded without a lower-level authorization guard, undermining the integrity and availability of ntopng's threat-intelligence monitoring. This issue is fixed in version 6.7.260717.

References

Affected packages

Azure Linux:3 / ntopng

Package

Name
ntopng
Purl
pkg:rpm/azure-linux/ntopng

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
5.2.1-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103404.json"