| Advisory ID | NN-2026:1-01 |
|---|---|
| Topic | Incorrect authorization for Threat Intelligence in Guardian/CMC before 26.0.0 |
| CWE Impact | CWE-863: Incorrect Authorization |
| Issue date | 2026-04-15 |
| Affects | Guardian, CMC < v26.0.0 |
| CVE Name(s) | CVE-2025-40897 |
| CVSS Details | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| CVSS Score | 7.2 (CVSS v4.0) 8.1 (CVSS v3.1) |
| CVE Risk Level | High (CVSS v4.0) High (CVSS v3.1) |
| Risk Level for Nozomi customers | High |
An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforced for users with view-only privileges.
An authenticated user with view-only privileges for the Threat Intelligence functionality can perform administrative actions on it, altering the rules configuration, and/or affecting their availability.
Guardian, CMC < v26.0.0
Remove or revoke access to Threat Intelligence users with view-only privileges until a fix is applied.
Upgrade to v26.0.0 or later.
We thank the following parties for their efforts: