CVE-2026-33391 MEDIUM

CVE-2026-33391: Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0

Vendor Nozomi Networks
Product Guardian
Weakness CWE-863 · Incorrect authorization
Published September 8, 2026
Last update September 8, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network.

Key dates

02Disclosure timeline

September 8, 2026 CVE published

Related vulnerabilities

04Related CVE