Skip to content
Nozomi NetworksCVE-2026-31984

Nozomi Networks CMC: denial of service

High8.7CVE-2026-31984 · Published Jul 9, 2026 · updated Aug 11, 2026

A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into audit entries. An unauthenticated attacker can submit requests containing excessively large input that is recorded into audit entries, possibly exhausting the available disk space and rendering the system inoperable.

Nozomi Networks advisory

Affected versions

PackageAffectedFixed in
CMC
Product
< 26.2.026.2.0
Guardian
Product
< 26.2.026.2.0
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-770

More Nozomi Networks advisories

All Nozomi Networks
Advisory
Nozomi Networks Arc: insecure default
Medium4.8Aug 11
When the upstream Guardian or CMC was configured in the Remote Collector via...
High8.3Jul 9
An Incorrect Privilege Assignment vulnerability was discovered in the...
High7.2Jul 9
Nozomi Networks Diagram tab: open redirect
Medium4.8Jul 9
Nozomi Networks SAML Single Sign-On functionality: open redirect
Medium5.3Jul 9
Nozomi Networks SSH keys synchronization endpoint: missing authentication
Medium6.9Jul 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.