Impact
ntopng releases prior to 6.7.260717 allow authenticated users who are not administrators to send POST requests to the REST v2 delete endpoints for notification listeners and recipients. This omission of an authorization check lets the attacker delete all configured notification endpoints and recipients, effectively silencing all alerting mechanisms and disrupting network monitoring.
Affected Systems
The vulnerability affects the ntop:ntopng product. Any installation using a version of ntopng earlier than 6.7.260717 is vulnerable. Older or custom builds that include the same Lua scripts without updated authorization logic are likewise impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a substantial impact on availability and confidence in monitoring. No EPSS value is available, but the lack of an authorization check means that any authenticated user can trigger the flaw. The exploit requires only standard HTTP POST credentials, so it can be performed by a local or remote user who has legitimate access to the web UI or API.
OpenCVE Enrichment