Authorization Bypass in ntopng REST v2 Handlers
An authorization bypass vulnerability in ntopng prior to version 6.7.260717 allows authenticated non-administrator users to delete notification endpoints and recipients, disrupting alerting services.
CVE search metadata
CVE search record: CVE-2026-86090. Severity: high. CVSS: 7.1. KEV: no. Product: ntopng (< 6.7.260717). Brief: Authorization Bypass in ntopng REST v2 Handlers. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ntopng-auth-bypass/
What's new
- 1. added detection rule: Detect CVE-2026-86091 Exploitation - Unauthorized Pool Deletion Attempt Sep 4, 23:28 via nvd
The ntopng network traffic analysis tool contains an authorization flaw in the REST v2 API handlers responsible for managing notification endpoints and recipients. Before version 6.7.260717, these delete endpoints fail to verify the administrative privileges of the requesting user. Any user authenticated to the ntopng instance can issue unauthorized POST requests to delete configured notification endpoints and recipients. This action is irreversible and effectively disables the alerting pipeline for the network monitoring system, leading to a denial of service for administrative visibility. Because ntopng is frequently deployed in sensitive network monitoring segments, this vulnerability provides a trivial path for an authenticated attacker with low-privilege access to silence security monitoring and evade detection during subsequent malicious activities.
Impact
The vulnerability results in a denial of service for the alerting capabilities of ntopng, which may be exploited by an authenticated attacker to mask ongoing unauthorized network activity. All sectors utilizing ntopng for network traffic analysis are affected. Successful exploitation allows for the permanent loss of notification configurations, requiring manual re-configuration by administrators.
Recommendation
Prioritized actions for detection and mitigation:
- Upgrade all ntopng instances to version 6.7.260717 or later to address CVE-2026-86090.
- Monitor webserver access logs for high-frequency or unauthorized POST requests to REST v2 endpoints related to notification settings.
- Restrict access to the ntopng management interface to authorized administrative segments only.
Immediate actions
Upgrade ntopng to 6.7.260717 or later.
Mitigations
Upgrade ntopng to version 6.7.260717.
CVE-2026-86090
Detection coverage 2
Detects CVE-2026-86090 Exploitation - Unauthorized REST API Calls in ntopng
highDetects potential exploitation of CVE-2026-86090 where a user attempts to access or delete notification endpoints via the ntopng REST v2 API.
Detect CVE-2026-86091 Exploitation - Unauthorized Pool Deletion Attempt
highDetects potential exploitation of CVE-2026-86091 by monitoring for POST requests to the pools bulk-delete endpoint.
Detection queries are available on the platform. Get full rules →