NN-2026:18-01

Cross-site request forgery in the Guardian/CMC login before 26.3.0

Last update: 2026-09-08

Advisory IDNN-2026:18-01
TopicCross-site request forgery in the Guardian/CMC login before 26.3.0
CWE ImpactCWE-352: Cross-Site Request Forgery (CSRF)
Issue date2026-09-08
AffectsGuardian, CMC < v26.3.0
CVE Name(s)CVE-2026-33920
CVSS DetailsCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CVSS Score5.1 (CVSS v4.0)
3.5 (CVSS v3.1)
CVE Risk LevelMedium (CVSS v4.0)
Low (CVSS v3.1)
Risk Level for Nozomi customersMedium

Summary

A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token.

Impact

An attacker with a valid account can trick a victim into unknowingly authenticating with the attacker's credentials. Any operation performed by the victim in this state is attributed to the attacker's account, compromising the integrity of the audit trail.

Affected Products

Guardian, CMC < v26.3.0

Workarounds and Mitigations

Users should always pay attention to phishing emails and untrusted links.

Solutions

Upgrade to v26.3.0 or later.

Modification History

2026-09-08: Initial revision

Related Links

Acknowledgements

We thank the following parties for their efforts:

  • one of our customers for finding this issue during a VAPT testing session

Contact

Nozomi Networks Product Security team can be reached at prodsec@nozominetworks.com.
More contact details on the PSIRT page.