{"id":"CVE-2026-84989","summary":"ntopng's Missing Authorization in REST API Allows Non-Admin Users to Delete and Rename Arbitrary Tags","details":"ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and `POST /lua/rest/v2/edit/tag/tag.lua` — perform no authorization check at all. Any authenticated user, including a non-administrator (\"unprivileged\") account, can delete or rename any tag in the system, including tags created by an administrator. Version 6.7.260718 contains a fix.","aliases":["GHSA-43p9-5758-wwq8"],"modified":"2026-09-05T03:48:31.347924138Z","published":"2026-09-03T14:47:01.859Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84989.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"6.7.0"},{"fixed":"6.7.260718"}]},{"extracted_events":[{"introduced":"6.7.0"},{"fixed":"6.7.260717"}],"source":"DESCRIPTION"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84989.json"},{"type":"ADVISORY","url":"https://github.com/ntop/ntopng/security/advisories/GHSA-43p9-5758-wwq8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84989"},{"type":"FIX","url":"https://github.com/ntop/ntopng/commit/0e41f24b367fb9caf750459da67827326e3289e8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ntop/ntopng","events":[{"introduced":"0"},{"fixed":"0e41f24b367fb9caf750459da67827326e3289e8"}],"database_specific":{"source":"REFERENCES"}}],"versions":["3.0","2.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84989.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"}]}