Nozomi NetworksCVE-2026-33922
Nozomi Networks Arc: path traversal
Medium6.8CVE-2026-33922 · Published Aug 11, 2026 · updated Aug 28, 2026
A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with administrative credentials for the web interface could submit an archive name containing traversal sequences and delete arbitrary files reachable by the Arc process, which runs with administrative privileges on the host.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Arc Product | < 2.7.0 | 2.7.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-22
More Nozomi Networks advisories
All Nozomi Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Nozomi Networks CMC: cross-site request forgery | Medium5.1 | Guardian 26.3.0+1 more |
| Sep 8 | Nozomi Networks Smart Polling: improper access control | Medium5.3 | Guardian 26.3.0+1 more |
| Sep 8 | Nozomi Networks Smart Polling functionality: attacker could access | Medium5.3 | Guardian 26.3.0+2 more |
| Sep 8 | Nozomi Networks Credentials Manager functionality: improper access control | Medium6.4 | Guardian 26.3.0+1 more |
| Sep 8 | Nozomi Networks Dashboards functionality: template injection | Medium5.1 | Guardian 26.3.0+1 more |
| Aug 11 | Nozomi Networks Arc: insecure default | Medium4.8 | 2.7.0 |