Description
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
Published: 2026-07-02
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ntopng versions up to 6.6 create HTTP session identifiers using a time‑seeded pseudo‑random number generator. The exposed web interface issues session cookies when a user logs in; because the seed is predictable, an attacker can cause two sessions to receive the same or an easily predicted cookie value. This deterministic or colliding session ID allows the attacker to hijack a legitimate authenticated session and impersonate a user. The weakness is defined as a Predictable Session Identifier (CWE-341).

Affected Systems

Any host running ntopng through 6.6 with the web interface exposed is affected. The vulnerability exists in all releases up to and including 6.6; it has been fixed in later versions and by applying the commits referenced in the advisory. Hosts that restrict web access or run newer versions are not susceptible.

Risk and Exploitability

The CVSS score of 9.8 reflects a high severity impact. The EPSS score is below 1 %, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the potential for session hijacking means that once an attacker obtains a predictable session cookie, they can gain full privileges. The likely attack vector is remote, via the web interface, where the attacker controls the timing of logins to generate a desired session ID.

Generated by OpenCVE AI on July 31, 2026 at 15:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ntopng to a patched version (≥6.7) or apply the commits referenced in the advisory.
  • Enable HTTPS and set session cookies to Secure and HttpOnly to prevent interception and reuse.
  • Implement rate limiting or CAPTCHAs on login attempts to make timing‑based prediction of session IDs more difficult.

Generated by OpenCVE AI on July 31, 2026 at 15:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Predictable HTTP Session ID Leading to Session Hijacking in ntopng 6.6

Mon, 27 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Predictable HTTP Session ID Leading to Session Hijacking in ntopng 6.6

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Vulnerability in ntopng 6.6

Tue, 21 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Vulnerability in ntopng 6.6

Fri, 17 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Leading to Session Hijacking in ntopng

Wed, 15 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Leading to Session Hijacking in ntopng

Tue, 14 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Leading to Session Hijacking in ntopng

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Leading to Session Hijacking in ntopng

Sun, 12 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Predictable HTTP Session Identifier Leading to Session Hijacking in ntopng 6.6

Sat, 11 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Predictable HTTP Session Identifier Leading to Session Hijacking in ntopng 6.6

Fri, 10 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Weak Session ID Generation in ntopng Enables Hijacking

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Weak Session ID Generation in ntopng Enables Hijacking

Thu, 09 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title ntopng Predictable Session Identifier Leading to Session Hijacking

Wed, 08 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title ntopng Predictable Session Identifier Leading to Session Hijacking

Tue, 07 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Predictable HTTP Session Identifier in ntopng 6.6 Allows Session Hijacking
Weaknesses CWE-330

Mon, 06 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Predictable HTTP Session Identifier in ntopng 6.6 Allows Session Hijacking
Weaknesses CWE-330

Mon, 06 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-341
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Leading to Session Hijacking in ntopng
Weaknesses CWE-330

Mon, 06 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Leading to Session Hijacking in ntopng
Weaknesses CWE-330

Sun, 05 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier in ntopng 6.6 Enables Session Hijacking
Weaknesses CWE-330

Sat, 04 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier in ntopng 6.6 Enables Session Hijacking
Weaknesses CWE-330

Sat, 04 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Predictable session identifiers allow session hijacking in ntopng
Weaknesses CWE-613

Sat, 04 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Predictable session identifiers allow session hijacking in ntopng
Weaknesses CWE-613

Fri, 03 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifiers Permit Session Hijacking in ntopng 6.6
Weaknesses CWE-613

Fri, 03 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifiers Permit Session Hijacking in ntopng 6.6
Weaknesses CWE-613

Thu, 02 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Ntop
Ntop ntopng
Vendors & Products Ntop
Ntop ntopng

Thu, 02 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-06T17:16:49.092Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38968

cve-icon Vulnrichment

Updated: 2026-07-06T17:15:55.314Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-02T21:16:55.170

Modified: 2026-07-08T18:39:19.380

Link: CVE-2026-38968

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T15:15:02Z

Weaknesses
  • CWE-341

    Predictable from Observable State