ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
References
Configurations
History
08 Jul 2026, 18:39
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:ntop:ntopng:*:*:*:*:*:*:*:* | |
| References | () https://github.com/ntop/ntopng/commit/14e22497233dc7d31d19dccb74b13bb073d16c2c - Patch | |
| References | () https://github.com/ntop/ntopng/commit/179a346ceb6239fd36128ccca3efa8f9ea61eeb5 - Patch | |
| First Time |
Ntop
Ntop ntopng |
06 Jul 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-341 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
02 Jul 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-02 21:16
Updated : 2026-07-08 18:39
NVD link : CVE-2026-38968
Mitre link : CVE-2026-38968
CVE.ORG link : CVE-2026-38968
JSON object : View
Products Affected
ntop
- ntopng
CWE
CWE-341
Predictable from Observable State
