Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-33388— Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0

Quick assessment

Affected
Nozomi Networks Guardian
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在凭据管理器(Credentials Manager)功能中,由于对用户权限的校验不足,发现了一个访问控制漏洞。一个拥有受限权限的远程认证用户能够查看可用凭据条目的一个有限子集。虽然实际的凭据值不会直接可见,但该用户仍然可以删除条目或编辑其属性。攻击者如果删除或编辑某个条目,可能会中断依赖该凭据的设备的认证过程;而如果攻击者能够操纵某个条目的配置,则可能间接获取其中的凭据。

CVSS 7.4 · High

Possible ATT&CK Techniques 2 AI

T1549.003 T1083.004

Affected Version Matrix 2

VendorProduct Version RangeStatus
Nozomi Networks CMC < 26.3.0 affected
Nozomi Networks Guardian < 26.3.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-33388

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0
Source: CVE Program / CVE List V5
Vulnerability Description
An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available entries in the Credentials Manager. The actual credential values are not directly visible, but the user can delete entries or edit their properties. An attacker who deletes or edits an entry can disrupt authentication for dependent devices, and one who manipulates an entry's configuration may be able to indirectly obtain the credentials.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Nozomi Networks Guardian 0 ~ 26.3.0 -
Nozomi Networks CMC 0 ~ 26.3.0 -

II. Public POCs for CVE-2026-33388

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-33388

登录查看更多情报信息。

Vendor Advisories for CVE-2026-33388 (1)

Same Patch Batch · Nozomi Networks · 2026-09-08 · 5 CVEs total

CVE-2026-33389 7.5 HIGH Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian
CVE-2026-33391 5.4 MEDIUM Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0
CVE-2026-33387 4.6 MEDIUM Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0
CVE-2026-33920 3.5 LOW Cross-site request forgery in the Guardian/CMC login before 26.3.0

IV. Related Vulnerabilities

V. Comments for CVE-2026-33388

No comments yet


Leave a comment