<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Ntopng (&lt; 6.7.260717) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ntopng--6.7.260717/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 04 Sep 2026 23:28:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ntopng--6.7.260717/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in ntopng REST v2 Handlers</title><link>https://feed.craftedsignal.io/briefs/2026-09-ntopng-auth-bypass/</link><pubDate>Fri, 04 Sep 2026 23:28:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ntopng-auth-bypass/</guid><description>An authorization bypass vulnerability in ntopng prior to version 6.7.260717 allows authenticated non-administrator users to delete notification endpoints and recipients, disrupting alerting services.</description><content:encoded><![CDATA[<p>The ntopng network traffic analysis tool contains an authorization flaw in the REST v2 API handlers responsible for managing notification endpoints and recipients. Before version 6.7.260717, these delete endpoints fail to verify the administrative privileges of the requesting user. Any user authenticated to the ntopng instance can issue unauthorized POST requests to delete configured notification endpoints and recipients. This action is irreversible and effectively disables the alerting pipeline for the network monitoring system, leading to a denial of service for administrative visibility. Because ntopng is frequently deployed in sensitive network monitoring segments, this vulnerability provides a trivial path for an authenticated attacker with low-privilege access to silence security monitoring and evade detection during subsequent malicious activities.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability results in a denial of service for the alerting capabilities of ntopng, which may be exploited by an authenticated attacker to mask ongoing unauthorized network activity. All sectors utilizing ntopng for network traffic analysis are affected. Successful exploitation allows for the permanent loss of notification configurations, requiring manual re-configuration by administrators.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for detection and mitigation:</p>
<ul>
<li>Upgrade all ntopng instances to version 6.7.260717 or later to address CVE-2026-86090.</li>
<li>Monitor webserver access logs for high-frequency or unauthorized POST requests to REST v2 endpoints related to notification settings.</li>
<li>Restrict access to the ntopng management interface to authorized administrative segments only.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>authentication-bypass</category><category>denial-of-service</category><category>vulnerability</category><category>authorization-bypass</category><category>ntopng</category></item></channel></rss>