CPE
high
advisory
Authorization Bypass in ntopng REST v2 Handlers
2 rules 2 TTPs 1 CVEAn authorization bypass vulnerability in ntopng prior to version 6.7.260717 allows authenticated non-administrator users to delete notification endpoints and recipients, disrupting alerting services.
ntopng
web-application
authentication-bypass
denial-of-service
vulnerability
authorization-bypass
2r
2t
1c
high
threat
CVE-2026-38968: ntopng Predictable Session Identifier Vulnerability Leading to Session Hijacking
1 CVECVE-2026-38968 affects ntopng versions up to 6.6, enabling session hijacking through predictable session identifiers generated with weak time-seeded pseudo-randomness in `src/HTTPserver.cpp`, allowing attackers to gain unauthorized access to legitimate user sessions.
exploited
ntopng through 6.6
session-hijacking
vulnerability
ntopng
network-monitoring
1c