CVE-2026-33391 PUBLISHED

Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0

Assigner: Nozomi
Reserved: 19.03.2026 Published: 08.09.2026 Updated: 08.09.2026

An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor Nozomi Networks
Product Guardian
Versions Default: unaffected
  • affected from 0 to 26.3.0 (excl.)
Vendor Nozomi Networks
Product CMC
Versions Default: unaffected
  • affected from 0 to 26.3.0 (excl.)

Workarounds

Review your Smart Polling discovery configuration.

Solutions

Upgrade to v26.3.0 or later.

Credits

  • This issue was found by one of our customers during a VAPT testing session. finder

References

Problem Types

  • CWE-863 Incorrect authorization CWE

Impacts

  • CAPEC-122 Privilege Abuse