ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and visibility restrictions that may bypass security policies.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 22:17
Updated : 2026-09-08 18:21
NVD link : CVE-2026-86091
Mitre link : CVE-2026-86091
CVE.ORG link : CVE-2026-86091
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
