CVE-2026-38968
CVE-2026-38968 is a critical-severity vulnerability in Ntop Ntopng with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-341.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- EPSS exploit prediction: 0% (31st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-341
- Affected product: Ntop Ntopng
- Published:
- Last modified:
Description
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
Frequently asked questions
- What is CVE-2026-38968?
- ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
- How severe is CVE-2026-38968?
- CVE-2026-38968 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-38968 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (31st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-38968?
- CVE-2026-38968 affects Ntop Ntopng. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-38968?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-38968 published?
- CVE-2026-38968 was published on 2026-07-02 and last updated on 2026-07-08.
References
- https://github.com/ntop/ntopng/commit/14e22497233dc7d31d19dccb74b13bb073d16c2c
- https://github.com/ntop/ntopng/commit/179a346ceb6239fd36128ccca3efa8f9ea61eeb5
Affected products (1)
- cpe:2.3:a:ntop:ntopng:*:*:*:*:*:*:*:*
More vulnerabilities in Ntop Ntopng
- CVE-2017-5473 — High (CVSS 8.8): Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the…
- CVE-2018-12520 — High (CVSS 8.1): An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not…
- CVE-2017-7458 — High (CVSS 7.5): The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a…
- CVE-2017-7459 — High (CVSS 7.5): ntopng before 3.0 allows HTTP Response Splitting.
- CVE-2017-7416 — Medium (CVSS 6.1): ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.
- CVE-2015-8368 — Medium (CVSS 6.0): ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the…
All CVEs affecting Ntop Ntopng →
Other CWE-341 vulnerabilities
- CVE-2026-42365 — High (CVSS 8.6): A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A…
- CVE-2025-40780 — High (CVSS 8.6): In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible…
- CVE-2026-15571 — High (CVSS 7.3): A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source…
- CVE-2025-48461 — Medium (CVSS 5.0): Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing…
- CVE-2025-42925 — Medium (CVSS 4.3): Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an…
- CVE-2024-10141 — Low (CVSS 3.7): A vulnerability, which was classified as problematic, was found in jsbroks COCO Annotator 0.11.1. This affects an…