Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to v26.3.0 or later.
Vendor Workaround
Use internal firewall features to limit access to the web management interface.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://security.nozominetworks.com/NN-2026:17-01 |
|
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network. | |
| Title | Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0 | |
| First Time appeared |
Nozomi Networks
Nozomi Networks cmc Nozomi Networks guardian |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:nozomi_networks:cmc:*:*:*:*:*:*:*:* cpe:2.3:a:nozomi_networks:guardian:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Nozomi Networks
Nozomi Networks cmc Nozomi Networks guardian |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2026-09-08T14:20:11.710Z
Reserved: 2026-03-19T11:28:43.172Z
Link: CVE-2026-33391
Updated: 2026-09-08T14:20:08.123Z
Status : Received
Published: 2026-09-08T14:17:22.547
Modified: 2026-09-08T15:18:43.500
Link: CVE-2026-33391
No data.
OpenCVE Enrichment
Updated: 2026-09-08T15:45:06Z
-
CWE-863
Incorrect Authorization