NN-2026:17-01

Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0

Last update: 2026-09-08

Advisory IDNN-2026:17-01
TopicIncorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0
CWE ImpactCWE-863: Incorrect Authorization
Issue date2026-09-08
AffectsGuardian, CMC < v26.3.0
CVE Name(s)CVE-2026-33391
CVSS DetailsCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS Score5.3 (CVSS v4.0)
5.4 (CVSS v3.1)
CVE Risk LevelMedium (CVSS v4.0)
Medium (CVSS v3.1)
Risk Level for Nozomi customersMedium

Summary

An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges.

Impact

An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network.

Affected Products

Guardian, CMC < v26.3.0

Workarounds and Mitigations

Use internal firewall features to limit access to the web management interface. Review all accounts with access to it and delete unnecessary ones. Review your Smart Polling discovery configuration.

Solutions

Upgrade to v26.3.0 or later.

Modification History

2026-09-08: Initial revision

Related Links

Acknowledgements

We thank the following parties for their efforts:

  • one of our customers for finding this issue during a VAPT testing session

Contact

Nozomi Networks Product Security team can be reached at prodsec@nozominetworks.com.
More contact details on the PSIRT page.