ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts. | |
| Title | ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers | |
| First Time appeared |
Ntop
Ntop ntopng |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:ntop:ntopng:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ntop
Ntop ntopng |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T21:48:46.991Z
Reserved: 2026-09-04T20:47:17.962Z
Link: CVE-2026-86090
No data.
Status : Received
Published: 2026-09-04T22:17:18.840
Modified: 2026-09-04T22:17:18.840
Link: CVE-2026-86090
No data.
OpenCVE Enrichment
No data.
Weaknesses