CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-38968

Critical · CVSS 9.8

ntopng — Predictable Session Identifier / Session Hijacking (CWE-341)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-341

Description

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.

Search profile — drives PoC discovery

Symbols HTTPserver.cppsession creationtime-seeded pseudo-randomnesssession cookies14e22497233dc7d31d19dccb74b13bb073d16c2c179a346ceb6239fd36128ccca3efa8f9ea61eeb5
Keywords CVE-2026-38968ntopng session hijackingntopng predictable sessionntopng weak session identifierntopng HTTPserver.cpp sessionntopng time-seeded PRNGntopng session cookie exploitntopng 6.6 vulnerabilityCWE-341 ntopng PoC
Versions: through 6.6

References

Status: enriched · ingested 2026-07-09T00:00:39.000Z · profiled 2026-07-09T00:30:39.000Z