| Advisory ID | NN-2026:17-01 |
|---|---|
| Topic | Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0 |
| CWE Impact | CWE-863: Incorrect Authorization |
| Issue date | 2026-09-08 |
| Affects | Guardian, CMC < v26.3.0 |
| CVE Name(s) | CVE-2026-33391 |
| CVSS Details | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
| CVSS Score | 5.3 (CVSS v4.0) 5.4 (CVSS v3.1) |
| CVE Risk Level | Medium (CVSS v4.0) Medium (CVSS v3.1) |
| Risk Level for Nozomi customers | Medium |
An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges.
An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network.
Guardian, CMC < v26.3.0
Use internal firewall features to limit access to the web management interface. Review all accounts with access to it and delete unnecessary ones. Review your Smart Polling discovery configuration.
Upgrade to v26.3.0 or later.
We thank the following parties for their efforts: