HIGH 7.1 NVD
CVE-2026-86090
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users ca
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.
References
- https://github.com/ntop/ntopng
- https://github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/r
- https://github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/r
- https://github.com/ntop/ntopng/commit/7d830f31af367745431c5d92e2e82fc432f6bdd8
- https://github.com/ntop/ntopng/security/advisories/GHSA-m22w-f647-vx88
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-04 via NVD.
vulnfeed aggregates 10149 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.