---
id: CVE-2026-86091
title: >-
  ntopng before 6.7.260717 fails to check user privileges in the pools
  bulk-delete endpoint, allowing authenticated non-administrators to delete all
  host pools and member bindings
summary: >-
  ntopng before 6.7.260717 fails to check user privileges in the pools
  bulk-delete endpoint, allowing authenticated non-administrators to delete all
  host pools and member bindings. Attackers can issue POST requests to the
  delete pools endp…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'
cwe:
  - CWE-862
vendor: ntop
product: ntopng
affected:
  - ntopng < 6.7.260717
published: '2026-09-04'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:46.847'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86091'
references:
  - url: 'https://github.com/ntop/ntopng'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/modules/pools/pools_rest_utils.lua
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/rest/v2/delete/pools.lua
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ntop/ntopng/commit/7d830f31af367745431c5d92e2e82fc432f6bdd8
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ntop/ntopng/security/advisories/GHSA-m22w-f647-vx88'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ntopng-before-6.7.260717-missing-authorization-on-the-host-pool-bulk-delete-handler
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ntop/ntopng/security/advisories/GHSA-m22w-f647-vx88'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00517
epssPercentile: 0.41417
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T17:56:46.291504Z'
ingestedAt: '2026-09-08T19:08:49.595Z'
---

## Overview

ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and visibility restrictions that may bypass security policies.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
