Impact
ntopng before version 6.7.260717 has a missing authorization check on its pools bulk‑delete REST endpoint, permitting any authenticated user who is not an administrator to delete all host pools and the bindings that link pools to traffic policies. This operation destroys visibility restrictions, traffic policy bindings and monitoring data, effectively removing network monitoring and potentially allowing traffic to bypass security controls. The vulnerability is a classic example of missing authorization (CWE‑862) and results in complete loss of critical network configuration.
Affected Systems
The affected vendors and products are ntop:ntopng, specifically all ntopng releases prior to 6.7.260717. The vulnerability is present in any ntopng installation that includes the pools_rest_utils.lua and delete/pools.lua REST scripts before the fix.
Risk and Exploitability
The CVSS base score of 7.1 classifies the issue as high severity, and although the EPSS score is not available, the lack of a CISA KEV listing does not diminish its potential impact. The attack requires a valid authenticated session, but an attacker does not need administrative privileges. The bulk‑delete endpoint can be invoked via a simple POST request, making exploitation straightforward for an internal or compromised account. Because the vulnerability removes all host pools, it leads to a denial of visibility and a possible bypass of traffic policy controls, which can cause significant operational disruption.
OpenCVE Enrichment