Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-33391— Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0

Quick assessment

Affected
Nozomi Networks Guardian
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Smart Polling(智能轮询)配置功能中发现了一个访问控制漏洞,原因是未充分校验用户权限。一个拥有有限权限的已认证用户可以远程绕过 Web 管理界面的预期访问控制,从而修改智能轮询的发现配置。这使得攻击者能够干扰受监控网络中资产的可观测性(可见性)。

CVSS 5.4 · Medium

Possible ATT&CK Techniques 1 AI

T1079

Affected Version Matrix 2

VendorProduct Version RangeStatus
Nozomi Networks CMC < 26.3.0 affected
Nozomi Networks Guardian < 26.3.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-33391

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0
Source: CVE Program / CVE List V5
Vulnerability Description
An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Nozomi Networks Guardian 0 ~ 26.3.0 -
Nozomi Networks CMC 0 ~ 26.3.0 -

II. Public POCs for CVE-2026-33391

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-33391

登录查看更多情报信息。

Vendor Advisories for CVE-2026-33391 (1)

Same Patch Batch · Nozomi Networks · 2026-09-08 · 5 CVEs total

CVE-2026-33389 7.5 HIGH Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian
CVE-2026-33388 7.4 HIGH Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0
CVE-2026-33387 4.6 MEDIUM Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0
CVE-2026-33920 3.5 LOW Cross-site request forgery in the Guardian/CMC login before 26.3.0

IV. Related Vulnerabilities

V. Comments for CVE-2026-33391

No comments yet


Leave a comment