Skip to content
Nozomi NetworksCVE-2026-33922

Nozomi Networks Arc: path traversal

Medium6.8CVE-2026-33922 · Published Aug 11, 2026 · updated Aug 28, 2026

A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with administrative credentials for the web interface could submit an archive name containing traversal sequences and delete arbitrary files reachable by the Arc process, which runs with administrative privileges on the host.

Nozomi Networks advisory

Affected versions

PackageAffectedFixed in
Arc
Product
< 2.7.02.7.0
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-22

More Nozomi Networks advisories

All Nozomi Networks
Advisory
Nozomi Networks CMC: cross-site request forgery
Medium5.1Sep 8
Nozomi Networks Smart Polling: improper access control
Medium5.3Sep 8
Nozomi Networks Smart Polling functionality: attacker could access
Medium5.3Sep 8
Nozomi Networks Credentials Manager functionality: improper access control
Medium6.4Sep 8
Nozomi Networks Dashboards functionality: template injection
Medium5.1Sep 8
Nozomi Networks Arc: insecure default
Medium4.8Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.