CVE-2026-38968

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ntop:ntopng:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-02 21:16

Updated : 2026-07-08 18:39


NVD link : CVE-2026-38968

Mitre link : CVE-2026-38968

CVE.ORG link : CVE-2026-38968


JSON object : View

Products Affected

ntop

  • ntopng
CWE
CWE-341

Predictable from Observable State