Skip to content
Threat Feed
high advisory

Authorization Bypass in ntopng REST v2 Handlers

An authorization bypass vulnerability in ntopng prior to version 6.7.260717 allows authenticated non-administrator users to delete notification endpoints and recipients, disrupting alerting services.

CVE search metadata

CVE search record: CVE-2026-86090. Severity: high. CVSS: 7.1. KEV: no. Product: ntopng (< 6.7.260717). Brief: Authorization Bypass in ntopng REST v2 Handlers. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ntopng-auth-bypass/

What's new

  • 1. added detection rule: Detect CVE-2026-86091 Exploitation - Unauthorized Pool Deletion Attempt Sep 4, 23:28 via nvd

The ntopng network traffic analysis tool contains an authorization flaw in the REST v2 API handlers responsible for managing notification endpoints and recipients. Before version 6.7.260717, these delete endpoints fail to verify the administrative privileges of the requesting user. Any user authenticated to the ntopng instance can issue unauthorized POST requests to delete configured notification endpoints and recipients. This action is irreversible and effectively disables the alerting pipeline for the network monitoring system, leading to a denial of service for administrative visibility. Because ntopng is frequently deployed in sensitive network monitoring segments, this vulnerability provides a trivial path for an authenticated attacker with low-privilege access to silence security monitoring and evade detection during subsequent malicious activities.

Impact

The vulnerability results in a denial of service for the alerting capabilities of ntopng, which may be exploited by an authenticated attacker to mask ongoing unauthorized network activity. All sectors utilizing ntopng for network traffic analysis are affected. Successful exploitation allows for the permanent loss of notification configurations, requiring manual re-configuration by administrators.

Recommendation

Prioritized actions for detection and mitigation:

  • Upgrade all ntopng instances to version 6.7.260717 or later to address CVE-2026-86090.
  • Monitor webserver access logs for high-frequency or unauthorized POST requests to REST v2 endpoints related to notification settings.
  • Restrict access to the ntopng management interface to authorized administrative segments only.

Immediate actions

Upgrade ntopng to 6.7.260717 or later.

IT Operations 48h

Mitigations

Upgrade ntopng to version 6.7.260717.

immediate IT Operations

CVE-2026-86090

Detection coverage 2

Detects CVE-2026-86090 Exploitation - Unauthorized REST API Calls in ntopng

high

Detects potential exploitation of CVE-2026-86090 where a user attempts to access or delete notification endpoints via the ntopng REST v2 API.

sigma tactics: impact sources: webserver

Detect CVE-2026-86091 Exploitation - Unauthorized Pool Deletion Attempt

high

Detects potential exploitation of CVE-2026-86091 by monitoring for POST requests to the pools bulk-delete endpoint.

sigma tactics: privilege-escalation sources: webserver

Detection queries are available on the platform. Get full rules →