Nozomi NetworksCVE-2026-33390
An Incorrect Privilege Assignment vulnerability was discovered in the...
High7.2CVE-2026-33390 · Published Jul 9, 2026 · updated Aug 11, 2026
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| CMC Product | < 26.2.0 | 26.2.0 |
| Guardian Product | < 26.2.0 | 26.2.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-266
More Nozomi Networks advisories
All Nozomi Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | Nozomi Networks Arc: insecure default | Medium4.8 | 2.7.0 |
| Jul 9 | When the upstream Guardian or CMC was configured in the Remote Collector via... | High8.3 | 26.2.0 |
| Jul 9 | Nozomi Networks Diagram tab: open redirect | Medium4.8 | Guardian 26.2.0+1 more |
| Jul 9 | Nozomi Networks SAML Single Sign-On functionality: open redirect | Medium5.3 | Guardian 26.2.0+1 more |
| Jul 9 | Nozomi Networks SSH keys synchronization endpoint: missing authentication | Medium6.9 | Guardian 26.2.0+1 more |
| Jul 9 | Nozomi Networks CMC: denial of service | High8.7 | Guardian 26.2.0+1 more |