{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-33391","assignerOrgId":"bec8025f-a851-46e5-b3a3-058e6b0aa23c","state":"PUBLISHED","assignerShortName":"Nozomi","dateReserved":"2026-03-19T11:28:43.172Z","datePublished":"2026-09-08T13:56:38.077Z","dateUpdated":"2026-09-08T14:20:11.710Z"},"containers":{"cna":{"providerMetadata":{"orgId":"bec8025f-a851-46e5-b3a3-058e6b0aa23c","shortName":"Nozomi","dateUpdated":"2026-09-08T13:56:38.077Z"},"title":"Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0","datePublic":"2026-09-08T07:00:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-863","description":"CWE-863 Incorrect authorization","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-122","descriptions":[{"lang":"en","value":"CAPEC-122 Privilege Abuse"}]}],"affected":[{"vendor":"Nozomi Networks","product":"Guardian","versions":[{"status":"affected","version":"0","lessThan":"26.3.0","versionType":"semver"}],"defaultStatus":"unaffected"},{"vendor":"Nozomi Networks","product":"CMC","versions":[{"status":"affected","version":"0","lessThan":"26.3.0","versionType":"semver"}],"defaultStatus":"unaffected"}],"cpeApplicability":[{"operator":"OR","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nozomi_networks:guardian:*:*:*:*:*:*:*:*","versionStartIncluding":"0","versionEndExcluding":"26.3.0"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nozomi_networks:cmc:*:*:*:*:*:*:*:*","versionStartIncluding":"0","versionEndExcluding":"26.3.0"}]}]}],"descriptions":[{"lang":"en","value":"An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network.","supportingMedia":[{"type":"text/html","base64":false,"value":"An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network."}]}],"references":[{"url":"https://security.nozominetworks.com/NN-2026:17-01"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseSeverity":"MEDIUM","baseScore":5.4,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"}}],"workarounds":[{"lang":"en","value":"Use internal firewall features to limit access to the web management interface.","supportingMedia":[{"type":"text/html","base64":false,"value":"Use internal firewall features to limit access to the web management interface.<br>"}]},{"lang":"en","value":"Review all accounts with access to it and delete unnecessary ones.","supportingMedia":[{"type":"text/html","base64":false,"value":"Review all accounts with access to it and delete unnecessary ones.<br>"}]},{"lang":"en","value":"Review your Smart Polling discovery configuration.","supportingMedia":[{"type":"text/html","base64":false,"value":"Review your Smart Polling discovery configuration.<br>"}]}],"solutions":[{"lang":"en","value":"Upgrade to v26.3.0 or later.","supportingMedia":[{"type":"text/html","base64":false,"value":"Upgrade to v26.3.0 or later.<br>"}]}],"credits":[{"lang":"en","value":"This issue was found by one of our customers during a VAPT testing session.","user":"00000000-0000-4000-9000-000000000000","type":"finder"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-08T14:20:04.040705Z","id":"CVE-2026-33391","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-08T14:20:11.710Z"}}]}}