SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86091

HIGH · CVSS 7.1 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows authenticated non-administrators in ntopng versions prior to 6.7.260717 to exploit the bulk-delete endpoint, enabling them to delete all host pools and associated member bindings. This can lead to the irreversible destruction of traffic policies and visibility restrictions, potentially bypassing established security measures. Organizations using ntopng should prioritize this issue to mitigate the risk of unauthorized data loss and disruption to network security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86091
Severity
HIGH
CVSS
7.1
EPSS
0.29%

Original NVD Description

ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and visibility restrictions that may bypass security policies.