CVE-2026-86090: ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ntopngto a version that resolves this vulnerability.Fixed in 6.7.260717
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated ntopng user who is not an administrator can exploit it. The attacker must be able to send POST requests to the affected REST v2 delete handlers.
What is the operational impact of a successful attack?
An attacker can irreversibly delete all configured notification endpoints and recipients. This can silence ntopng alerts by removing the destinations and recipients used for notifications.
Which deployments should be prioritized for remediation?
Deployments running ntopng versions before 6.7.260717 should be prioritized, particularly where non-administrator accounts exist and notification endpoints or recipients are configured.