ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and visibility restrictions that may bypass security policies.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and visibility restrictions that may bypass security policies. | |
| Title | ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler | |
| First Time appeared |
Ntop
Ntop ntopng |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:ntop:ntopng:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ntop
Ntop ntopng |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-04T21:48:47.663Z
Updated: 2026-09-08T17:57:14.089Z
Reserved: 2026-09-04T20:47:22.899Z
Link: CVE-2026-86091
Updated: 2026-09-08T17:57:08.243Z
Status : Received
Published: 2026-09-04T22:17:18.990
Modified: 2026-09-08T18:21:14.423
Link: CVE-2026-86091
No data.