Overview
Description
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.
Statistics
- 2 Posts
Last activity: 19 hours ago
Bluesky
ntopng: apply patch for CVE-2026-86091 CVE-2026-86090
https://github.com/NixOS/nixpkgs/pull/560316
https://tracker.security.nixos.org/issues/NIXPKGS-2026-2510
#security
Overview
Description
ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and visibility restrictions that may bypass security policies.
Statistics
- 2 Posts
Last activity: 19 hours ago
Bluesky
ntopng: apply patch for CVE-2026-86091 CVE-2026-86090
https://github.com/NixOS/nixpkgs/pull/560316
https://tracker.security.nixos.org/issues/NIXPKGS-2026-2510
#security