漏洞概述 漏洞名称: Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0 漏洞ID: NN-2026-9-01 CVE ID: CVE-2026-31882 CWE Impact: CWE-601: URL Redirection to Untrusted Site ('Open Redirect') CVSS Score: 5.3 (CVSS v4.0), 7.1 (CVSS v3.1) Issue Date: 2026-07-07 Last Update: 2026-07-07 影响范围 受影响产品: Guardian, CMC < v26.2.0 风险等级: Medium (CVSS v4.0), High (CVSS v3.1) 对Nozomi客户的影响: Medium 修复方案 解决方案: 升级到 v26.2.0 或更高版本。 临时缓解措施: 使用内部防火墙功能限制对Web管理界面的访问。 相关链接 Mitre CVE entry 致谢 Andrea Palanca of Nozomi Networks Product Security team for finding this issue during an internal investigation 联系方式 Nozomi Networks Product Security team can be reached at prodsec@nozominetworks.com. More contact details on the PSIRT page.