CVE-2026-86090
Received Received - Intake

ntopng Authorization Bypass Leads to Alert Deletion

Vulnerability report for CVE-2026-86090, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: VulnCheck

Description

ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ntopng ntopng to 6.7.260717 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ntopng before version 6.7.260717 has a flaw where authorization checks are missing in delete endpoints and REST v2 handlers for notification recipients. This allows authenticated non-admin users to send POST requests to permanently delete all configured notification endpoints and recipients, which would silence all alerts.

Detection Guidance

Detecting this vulnerability requires checking if ntopng is running a vulnerable version (before 6.7.260717). Check the version with: ntopng --version. Also review logs for POST requests to /lua/delete_endpoint.lua or /lua/admin/recipients.lua endpoints by non-admin users.

Impact Analysis

If exploited, this vulnerability could allow an attacker with valid but limited access to disrupt monitoring and alerting systems by deleting all notification endpoints and recipients. This could prevent critical alerts from being sent, potentially leading to undetected security incidents or system failures.

Compliance Impact

This vulnerability could impact compliance by preventing timely detection and response to security events, which may violate requirements for monitoring, logging, and incident response under standards like GDPR and HIPAA. Failure to maintain proper alerting could result in non-compliance and associated penalties.

Mitigation Strategies

Upgrade ntopng to version 6.7.260717 or later immediately. Restrict access to administrative functions for non-admin users. Monitor network traffic for suspicious POST requests to delete endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86090. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart