Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99690.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-99690
Upstream
Published
2026-09-04T22:17:18Z
Modified
2026-09-05T14:15:11.322839061Z
Summary
CVE-2026-86090 affecting package ntopng 5.2.1-6
Details

ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.

References

Affected packages

Azure Linux:3 / ntopng

Package

Name
ntopng
Purl
pkg:rpm/azure-linux/ntopng

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
5.2.1-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99690.json"