CVE-2026-33391

Summary

An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network.

Affected Software

VendorProductVersion RangeStatus
Nozomi NetworksGuardian0 < 26.3.0affected
Nozomi NetworksCMC0 < 26.3.0affected

Weaknesses

  • CWE-863: CWE-863 Incorrect authorization

Workarounds

Use internal firewall features to limit access to the web management interface. Review all accounts with access to it and delete unnecessary ones. Review your Smart Polling discovery configuration.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References