Skip to content
Nozomi NetworksCVE-2026-33387

Nozomi Networks Dashboards functionality: template injection

Medium5.1CVE-2026-33387 · Published Sep 8, 2026

A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered into importing a malicious dashboard. When the victim views or imports the dashboard, the payload executes in their browser context, allowing the attacker to modify application data or disrupt application availability.

Nozomi Networks advisory

Affected versions

PackageAffectedFixed in
CMC
Product
< 26.3.026.3.0
Guardian
Product
< 26.3.026.3.0
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-1336

More Nozomi Networks advisories

All Nozomi Networks
Advisory
Nozomi Networks Credentials Manager functionality: improper access control
Medium6.4Sep 8
Nozomi Networks Smart Polling functionality: attacker could access
Medium5.3Sep 8
Nozomi Networks Smart Polling: improper access control
Medium5.3Sep 8
Nozomi Networks CMC: cross-site request forgery
Medium5.1Sep 8
Nozomi Networks Arc: path traversal
Medium6.8Aug 11
Nozomi Networks Arc: insecure default
Medium4.8Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.