Skip to content
Nozomi NetworksCVE-2026-33390

An Incorrect Privilege Assignment vulnerability was discovered in the...

High7.2CVE-2026-33390 · Published Jul 9, 2026 · updated Aug 11, 2026

An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.

Nozomi Networks advisory

Affected versions

PackageAffectedFixed in
CMC
Product
< 26.2.026.2.0
Guardian
Product
< 26.2.026.2.0
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-266

More Nozomi Networks advisories

All Nozomi Networks
Advisory
Nozomi Networks Arc: insecure default
Medium4.8Aug 11
When the upstream Guardian or CMC was configured in the Remote Collector via...
High8.3Jul 9
Nozomi Networks Diagram tab: open redirect
Medium4.8Jul 9
Nozomi Networks SAML Single Sign-On functionality: open redirect
Medium5.3Jul 9
Nozomi Networks SSH keys synchronization endpoint: missing authentication
Medium6.9Jul 9
Nozomi Networks CMC: denial of service
High8.7Jul 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.