High severity7.1NVD Advisory· Published Sep 4, 2026
CVE-2026-86091
CVE-2026-86091
Description
ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and visibility restrictions that may bypass security policies.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/modules/pools/pools_rest_utils.luanvd
- github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/rest/v2/delete/pools.luanvd
- github.com/ntop/ntopng/commit/7d830f31af367745431c5d92e2e82fc432f6bdd8nvd
- github.com/ntop/ntopng/security/advisories/GHSA-m22w-f647-vx88nvd
- www.vulncheck.com/advisories/ntopng-before-6.7.260717-missing-authorization-on-the-host-pool-bulk-delete-handlernvd
News mentions
0No linked articles in our index yet.