← Terug naar overzicht

ntopng versions before 6.7.260717 contain a missing authorization vulnerability in the pools bulk-delete endpoint. Authenticated non-administrator users can send POST requests to the delete pools endpoint to irreversibly destroy all host pools and member bindings. This flaw allows attackers to remove traffic policy bindings and visibility restrictions, potentially bypassing security policies. The vulnerability stems from the application's failure to check user privileges before performing destructive administrative actions. A fix was committed and documented in the ntopng GitHub repository and security advisory GHSA-m22w-f647-vx88. Users are advised to upgrade to version 6.7.260717 or later to remediate this issue.

Affected products

  • ntopng

Related CVE's

  • CVE-2026-86091

Categories

  • Identity & Access
  • Network Infrastructure