Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-38968: ntopng versions 1 to 6.6 can be hijacked by session thieves
CVE-2026-38968
CVE-2026-38968
Summary
If you use ntopng to monitor network traffic, an attacker could potentially take control of your account by guessing your session ID. This is because ntopng generates session IDs in a way that's predictable, making it easier for an attacker to hijack your session. To stay safe, update to ntopng version 6.7 or later.
Original title
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during ...
Original description
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
Vulnerability type
CWE-341
Published: 2 Jul 2026 · Updated: 23 Jul 2026 · First seen: 2 Jul 2026