ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
References
Configurations
History
No history.
Information
Published : 2026-07-02 21:16
Updated : 2026-07-08 18:39
NVD link : CVE-2026-38968
Mitre link : CVE-2026-38968
CVE.ORG link : CVE-2026-38968
JSON object : View
Products Affected
ntop
- ntopng
CWE
CWE-341
Predictable from Observable State
