CVE-2026-33920 PUBLISHED

Cross-site request forgery in the Guardian/CMC login before 26.3.0

Assigner: Nozomi
Reserved: 24.03.2026 Published: 08.09.2026 Updated: 08.09.2026

A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can trick a victim into unknowingly authenticating with the attacker's credentials. Any operation performed by the victim in this state is attributed to the attacker's account, compromising the integrity of the audit trail.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor Nozomi Networks
Product Guardian
Versions Default: unaffected
  • affected from 0 to 26.3.0 (excl.)
Vendor Nozomi Networks
Product CMC
Versions Default: unaffected
  • affected from 0 to 26.3.0 (excl.)

Workarounds

Users should always pay attention to phishing emails and untrusted links.

Solutions

Upgrade to v26.3.0 or later.

Credits

  • This issue was found by one of our customers during a VAPT testing session. finder

References

Problem Types

  • CWE-352 Cross-site request forgery (CSRF) CWE

Impacts

  • CAPEC-62 Cross Site Request Forgery