CVE-2026-38968

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ntop:ntopng:*:*:*:*:*:*:*:*

History

08 Jul 2026, 18:39

Type Values Removed Values Added
CPE cpe:2.3:a:ntop:ntopng:*:*:*:*:*:*:*:*
References () https://github.com/ntop/ntopng/commit/14e22497233dc7d31d19dccb74b13bb073d16c2c - () https://github.com/ntop/ntopng/commit/14e22497233dc7d31d19dccb74b13bb073d16c2c - Patch
References () https://github.com/ntop/ntopng/commit/179a346ceb6239fd36128ccca3efa8f9ea61eeb5 - () https://github.com/ntop/ntopng/commit/179a346ceb6239fd36128ccca3efa8f9ea61eeb5 - Patch
First Time Ntop
Ntop ntopng

06 Jul 2026, 18:16

Type Values Removed Values Added
CWE CWE-341
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

02 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-02 21:16

Updated : 2026-07-08 18:39


NVD link : CVE-2026-38968

Mitre link : CVE-2026-38968

CVE.ORG link : CVE-2026-38968


JSON object : View

Products Affected

ntop

  • ntopng
CWE
CWE-341

Predictable from Observable State