HIGHVulnerability

CVE-2026-86090

ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.

Properties

severity
HIGH
score
7.1
cve_id
CVE-2026-86090
signal_observed_at
2026-09-16T17:34:22+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
published_at
2026-09-04T22:17:18.840
last_modified
2026-09-14T20:17:00.337

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph