CVE-2026-38968
Critical · CVSS 9.8ntopng — Predictable Session Identifier / Session Hijacking (CWE-341)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-341
Description
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
Search profile — drives PoC discovery
Symbols HTTPserver.cppsession creationtime-seeded pseudo-randomnesssession cookies14e22497233dc7d31d19dccb74b13bb073d16c2c179a346ceb6239fd36128ccca3efa8f9ea61eeb5
Keywords CVE-2026-38968ntopng session hijackingntopng predictable sessionntopng weak session identifierntopng HTTPserver.cpp sessionntopng time-seeded PRNGntopng session cookie exploitntopng 6.6 vulnerabilityCWE-341 ntopng PoC
Versions: through 6.6
References
Status: enriched · ingested 2026-07-09T00:00:39.000Z · profiled 2026-07-09T00:30:39.000Z