Beveiligingsadvies

CVE-2026-86091

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-04 21:48:47
Laatst bijgewerkt 2026-09-08 17:57:14
Toegewezen door VulnCheck
CVSS-score 7.1
Status PUBLISHED

Beschrijving

ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and visibility restrictions that may bypass security policies.