Skip to content
Nozomi NetworksCVE-2026-31985

When the upstream Guardian or CMC was configured in the Remote Collector via...

High8.3CVE-2026-31985 · Published Jul 9, 2026

When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verification, and no option was provided to enable it. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Remote Collector and the Guardian or CMC. This could result in theft of the sync token, impersonation of the server, injection of spoofed data (such as false asset information or vulnerabilities) into the Guardian or CMC, or disruption of the data flow between the Remote Collector and the Guardian or CMC.

Nozomi Networks advisory

Affected versions

PackageAffectedFixed in
Remote Collector
Product
< 26.2.026.2.0
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-671

More Nozomi Networks advisories

All Nozomi Networks
Advisory
Nozomi Networks Arc: insecure default
Medium4.8Aug 11
An Incorrect Privilege Assignment vulnerability was discovered in the...
High7.2Jul 9
Nozomi Networks Diagram tab: open redirect
Medium4.8Jul 9
Nozomi Networks SAML Single Sign-On functionality: open redirect
Medium5.3Jul 9
Nozomi Networks SSH keys synchronization endpoint: missing authentication
Medium6.9Jul 9
Nozomi Networks CMC: denial of service
High8.7Jul 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.