Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-33387— Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0

Quick assessment

Affected
Nozomi Networks Guardian
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Dashboards(仪表盘)功能中发现了模板注入漏洞,原因是输入参数未进行适当验证。拥有相应权限的已认证用户可以定义包含恶意载荷的仪表盘,或者受害者可能被社会工程攻击诱导导入恶意仪表盘。当受害者查看或导入该仪表盘时,载荷将在其浏览器上下文中执行,使攻击者能够修改应用程序数据或破坏应用程序的可用性。

CVSS 4.6 · Medium

Affected Version Matrix 2

VendorProduct Version RangeStatus
Nozomi Networks CMC < 26.3.0 affected
Nozomi Networks Guardian < 26.3.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-33387

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0
Source: CVE Program / CVE List V5
Vulnerability Description
A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered into importing a malicious dashboard. When the victim views or imports the dashboard, the payload executes in their browser context, allowing the attacker to modify application data or disrupt application availability.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1336
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Nozomi Networks Guardian 0 ~ 26.3.0 -
Nozomi Networks CMC 0 ~ 26.3.0 -

II. Public POCs for CVE-2026-33387

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-33387

登录查看更多情报信息。

Vendor Pages for CVE-2026-33387 (1)

Same Patch Batch · Nozomi Networks · 2026-09-08 · 5 CVEs total

CVE-2026-33389 7.5 HIGH Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian
CVE-2026-33388 7.4 HIGH Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0
CVE-2026-33391 5.4 MEDIUM Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0
CVE-2026-33920 3.5 LOW Cross-site request forgery in the Guardian/CMC login before 26.3.0

IV. Related Vulnerabilities

V. Comments for CVE-2026-33387

No comments yet


Leave a comment