Authorization Flaw in ntopng Affects Deletion of Notification Endpoints and Recipients
CVE-2026-86090

7.1HIGH

Key Information:

Vendor

Ntop

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-86090?

An authorization error exists in ntopng prior to version 6.7.260717, allowing authenticated non-administrator users to interact with deletion endpoints in the REST API without proper checks. This flaw permits these users to issue POST requests that can irreversibly delete all configured notification endpoints and recipients. As a result, it can lead to the silencing of critical alerts in the system.

Affected Version(s)

ntopng 0 < 6.7.260717

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.