CVE-2026-86090 - ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers
CVE ID :CVE-2026-86090
Published : Sept. 4, 2026, 10:17 p.m. | 47 minutes ago
Description :ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 4, 2026, 10:17 p.m. | 47 minutes ago
Description :ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...