{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ntopng--6.7.260717/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ntop:ntopng:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-86090"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ntopng (\u003c 6.7.260717)"],"_cs_severities":["high"],"_cs_tags":["web-application","authentication-bypass","denial-of-service","vulnerability","authorization-bypass","ntopng"],"_cs_type":"advisory","_cs_vendors":["ntop"],"content_html":"\u003cp\u003eThe ntopng network traffic analysis tool contains an authorization flaw in the REST v2 API handlers responsible for managing notification endpoints and recipients. Before version 6.7.260717, these delete endpoints fail to verify the administrative privileges of the requesting user. Any user authenticated to the ntopng instance can issue unauthorized POST requests to delete configured notification endpoints and recipients. This action is irreversible and effectively disables the alerting pipeline for the network monitoring system, leading to a denial of service for administrative visibility. Because ntopng is frequently deployed in sensitive network monitoring segments, this vulnerability provides a trivial path for an authenticated attacker with low-privilege access to silence security monitoring and evade detection during subsequent malicious activities.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a denial of service for the alerting capabilities of ntopng, which may be exploited by an authenticated attacker to mask ongoing unauthorized network activity. All sectors utilizing ntopng for network traffic analysis are affected. Successful exploitation allows for the permanent loss of notification configurations, requiring manual re-configuration by administrators.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and mitigation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all ntopng instances to version 6.7.260717 or later to address CVE-2026-86090.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for high-frequency or unauthorized POST requests to REST v2 endpoints related to notification settings.\u003c/li\u003e\n\u003cli\u003eRestrict access to the ntopng management interface to authorized administrative segments only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T23:28:15Z","date_published":"2026-09-04T23:28:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ntopng-auth-bypass/","summary":"An authorization bypass vulnerability in ntopng prior to version 6.7.260717 allows authenticated non-administrator users to delete notification endpoints and recipients, disrupting alerting services.","title":"Authorization Bypass in ntopng REST v2 Handlers","url":"https://feed.craftedsignal.io/briefs/2026-09-ntopng-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Ntopng (\u003c 6.7.260717)","version":"https://jsonfeed.org/version/1.1"}