Nozomi NetworksCVE-2026-33920
Nozomi Networks CMC: cross-site request forgery
Medium5.1CVE-2026-33920 · Published Sep 8, 2026
A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can trick a victim into unknowingly authenticating with the attacker's credentials. Any operation performed by the victim in this state is attributed to the attacker's account, compromising the integrity of the audit trail.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| CMC Product | < 26.3.0 | 26.3.0 |
| Guardian Product | < 26.3.0 | 26.3.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-352
More Nozomi Networks advisories
All Nozomi Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Nozomi Networks Dashboards functionality: template injection | Medium5.1 | Guardian 26.3.0+1 more |
| Sep 8 | Nozomi Networks Credentials Manager functionality: improper access control | Medium6.4 | Guardian 26.3.0+1 more |
| Sep 8 | Nozomi Networks Smart Polling functionality: attacker could access | Medium5.3 | Guardian 26.3.0+2 more |
| Sep 8 | Nozomi Networks Smart Polling: improper access control | Medium5.3 | Guardian 26.3.0+1 more |
| Aug 11 | Nozomi Networks Arc: path traversal | Medium6.8 | 2.7.0 |
| Aug 11 | Nozomi Networks Arc: insecure default | Medium4.8 | 2.7.0 |