Description
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
Published: 2026-07-02
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ntopng releases up to 6.6 generate HTTP session identifiers using a weak, time‑seeded pseudo‑random number generator during session creation. Fresh authenticated logins can receive deterministic or colliding session cookies when timing is controlled by an attacker, allowing the attacker to hijack authenticated sessions and impersonate the legitimate user. The flaw is a Predictable Session Identifier weakness (CWE-341).

Affected Systems

Any host running ntopng 6.6 or earlier with the web interface exposed is vulnerable. The issue exists in all releases through 6.6 and is fixed in later versions.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. However, the impact of session hijacking is severe; an attacker who can predict or force a collision can immediately assume a user’s privileges. The CVSS score of 9.8 indicates a high severity of this flaw. The risk is therefore high enough that organizations should remediate promptly despite the low exploitation probability.

Generated by OpenCVE AI on July 21, 2026 at 12:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ntopng to a patched version (≥6.7 or apply the commits referenced in the advisory).
  • Enable HTTPS for the web interface and configure session cookies to be Secure and HttpOnly to prevent interception and reuse.
  • Implement rate limiting or a CAPTCHA on login attempts to make timing‑based prediction of session IDs more difficult.

Generated by OpenCVE AI on July 21, 2026 at 12:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Vulnerability in ntopng 6.6

Fri, 17 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Leading to Session Hijacking in ntopng

Wed, 15 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Leading to Session Hijacking in ntopng

Tue, 14 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Leading to Session Hijacking in ntopng

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Leading to Session Hijacking in ntopng

Sun, 12 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Predictable HTTP Session Identifier Leading to Session Hijacking in ntopng 6.6

Sat, 11 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Predictable HTTP Session Identifier Leading to Session Hijacking in ntopng 6.6

Fri, 10 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Weak Session ID Generation in ntopng Enables Hijacking

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Weak Session ID Generation in ntopng Enables Hijacking

Thu, 09 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title ntopng Predictable Session Identifier Leading to Session Hijacking

Wed, 08 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title ntopng Predictable Session Identifier Leading to Session Hijacking

Tue, 07 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Predictable HTTP Session Identifier in ntopng 6.6 Allows Session Hijacking
Weaknesses CWE-330

Mon, 06 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Predictable HTTP Session Identifier in ntopng 6.6 Allows Session Hijacking
Weaknesses CWE-330

Mon, 06 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-341
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Leading to Session Hijacking in ntopng
Weaknesses CWE-330

Mon, 06 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier Leading to Session Hijacking in ntopng
Weaknesses CWE-330

Sun, 05 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier in ntopng 6.6 Enables Session Hijacking
Weaknesses CWE-330

Sat, 04 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifier in ntopng 6.6 Enables Session Hijacking
Weaknesses CWE-330

Sat, 04 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Predictable session identifiers allow session hijacking in ntopng
Weaknesses CWE-613

Sat, 04 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Predictable session identifiers allow session hijacking in ntopng
Weaknesses CWE-613

Fri, 03 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifiers Permit Session Hijacking in ntopng 6.6
Weaknesses CWE-613

Fri, 03 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Predictable Session Identifiers Permit Session Hijacking in ntopng 6.6
Weaknesses CWE-613

Thu, 02 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Ntop
Ntop ntopng
Vendors & Products Ntop
Ntop ntopng

Thu, 02 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-06T17:16:49.092Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38968

cve-icon Vulnrichment

Updated: 2026-07-06T17:15:55.314Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:45:02Z

Weaknesses
  • CWE-341

    Predictable from Observable State