PatchSiren cyber security CVE debrief
CVE-2026-86091 ntop CVE debrief
CVE-2026-86091 is a high-severity vulnerability in ntopng, a network traffic monitoring tool, that allows authenticated non-administrators to delete all host pools and member bindings due to a lack of proper authorization checks in the pools bulk-delete endpoint. This vulnerability can disrupt network visibility and security policy enforcement, potentially leading to unauthorized changes to network configurations. Network administrators, security teams, and IT personnel responsible for managing and monitoring network traffic using ntopng should be aware of this vulnerability and take steps to verify and remediate it. The CVE record and NVD entry provide details on the vulnerability
- Vendor
- ntop
- Product
- ntopng
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-04
- Original CVE updated
- 2026-09-23
- Advisory published
- 2026-09-04
- Advisory updated
- 2026-09-23
Who should care
Network administrators, security teams, and IT personnel responsible for managing and monitoring network traffic using ntopng should be aware of this vulnerability and take steps to verify and remediate it.
Why it matters
CVE-2026-86091 is a high-severity vulnerability in ntopng that allows authenticated non-administrators to delete host pools and member bindings, potentially disrupting network visibility and security policy enforcement. Defenders should prioritize verifying and remediating this vulnerability, especially in environments where ntopng is used to monitor and manage network traffic.
- Disruption of network visibility and security policy enforcement.
- Potential removal of traffic policy bindings and visibility restrictions.
- Increased risk of unauthorized changes to network configurations.
- Need for verification of ntopng version and exposure.
Technical summary
The vulnerability exists in the pools bulk-delete endpoint of ntopng, where authenticated non-administrators can issue POST requests to delete all host pools and member bindings, effectively bypassing security policies and removing visibility restrictions. This can lead to significant disruptions in network visibility and security policy enforcement, especially in environments where ntopng is used to monitor and manage network traffic. Defenders should prioritize verifying and remediating this vulnerability to prevent potential exploitation.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability, especially in environments where ntopng is used to monitor and manage network traffic, as exploitation could lead to significant disruptions in network visibility and security policy enforcement.
Recommended defensive actions
- Verify the version of ntopng in use and check if it is vulnerable to this issue.
- Restrict access to the pools bulk-delete endpoint to only administrators.
- Implement additional monitoring and logging to detect potential exploitation attempts.
- Consider upgrading to a version of ntopng that addresses this vulnerability, if available.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. However, the exact versions of ntopng that are vulnerable or patched are not specified in the provided corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86091 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86091
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86091 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86091
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ntop/ntopng
-
Source reference
Unverified legacy reference
URL: https://github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/modules/pools/pools_rest_utils.lua
-
Source reference
Unverified legacy reference
URL: https://github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/rest/v2/delete/pools.lua
-
Source reference
Unverified legacy reference
URL: https://github.com/ntop/ntopng/commit/7d830f31af367745431c5d92e2e82fc432f6bdd8
-
Source reference
Unverified legacy reference
URL: https://github.com/ntop/ntopng/security/advisories/GHSA-m22w-f647-vx88
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/ntopng-before-6.7.260717-missing-authorization-on-the-host-pool-bulk-delete-handler
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.