ntopng 在 6.7.260717 之前的版本中,其删除端点及 recipients REST v2 处理器未能正确执行授权检查。经过认证的非管理员用户可以向这些端点发送 POST 请求,不可逆地删除所有已配置的通知端点和接收者,从而导致所有告警被静默(即所有告警通知被阻止)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86098 | 7.4 HIGH | ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape |
| CVE-2026-86091 | 7.1 HIGH | ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler |
No comments yet