CVE-2026-86091
Received Received - Intake

ntopng Privilege Escalation in Pools Bulk-Delete Endpoint

Vulnerability report for CVE-2026-86091, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: VulnCheck

Description

ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and visibility restrictions that may bypass security policies.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ntopng ntopng to 6.7.260717 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ntopng before version 6.7.260717 has a flaw where it does not verify user privileges in the pools bulk-delete endpoint. This allows authenticated users who are not administrators to delete all host pools and their member bindings. Attackers can send POST requests to this endpoint to permanently remove all host pools, which also deletes traffic policy bindings and visibility restrictions that enforce security policies.

Detection Guidance

Check ntopng logs for POST requests to the pools bulk-delete endpoint (/lua/delete_pools.lua) from non-admin users. Monitor for sudden disappearance of host pools or traffic policy bindings.

Impact Analysis

If exploited, this vulnerability could allow unauthorized users to delete critical host pools and their configurations. This may lead to loss of traffic monitoring, bypassed security policies, and reduced network visibility. Organizations relying on ntopng for traffic management and security could face operational disruptions and increased risk of undetected malicious activity.

Compliance Impact

This vulnerability could impact compliance by disrupting network monitoring and security controls required by standards like GDPR and HIPAA. Loss of traffic visibility and policy enforcement may result in non-compliance with data protection and security requirements, potentially leading to legal and regulatory penalties.

Mitigation Strategies

Upgrade ntopng to version 6.7.260717 or later. Restrict access to administrative functions and review user privileges. Implement network monitoring to detect unauthorized deletion attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86091. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart