PT-2026-55303 · Ntopng · Ntopng

CVE-2026-38968

·

Published

2026-07-02

·

Updated

2026-07-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ntopng versions prior to 6.7
Description Predictable session identifiers can lead to session hijacking. The issue occurs because HTTP session identifiers in the src/HTTPserver.cpp file use weak time-seeded pseudo-randomness during session creation. This allows fresh authenticated logins to receive deterministic or colliding session cookies if the timing is controlled by an attacker.
Recommendations Update ntopng to a version later than 6.6.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92103
CVE-2026-38968

Affected Products

Ntopng