CVE-2026-86090 ntopng before 6.7.260717 fails to perform… — CVE Notify — TG.ME

🚨 CVE-2026-86090
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.

🎖@cveNotify
GitHub
GitHub - ntop/ntopng: Web-based Traffic and Cybersecurity Network Traffic Monitoring
Web-based Traffic and Cybersecurity Network Traffic Monitoring - ntop/ntopng
September 4, 2026 19