Description
A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data through multiple input vectors. When a victim views the affected data in the Diagram tab and Graph view, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.
Published: 2026-07-09
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stored HTML injection flaw exists in the Diagram tab and Graph view of Nozomi Networks’ CMC and Guardian products when running any release earlier than 26.2.0. An authenticated user with administrative privileges can insert malicious HTML tags into N2OS configuration data through multiple input vectors. When another user views the affected data in the diagram or graph view, the injected HTML renders in their browser. This rendering can be used to conduct phishing or open‑redirect attacks, even though full cross‑site scripting exploitation and direct information disclosure are mitigated by existing input validation and Content‑Security‑Policy settings.

Affected Systems

Nozomi Networks’ CMC and Guardian products are vulnerable in any release prior to 26.2.0. The vulnerability affects installations that expose the diagram and graph interfaces to web users.

Risk and Exploitability

The CVSS score of 4.8 places this issue in the medium severity range, and the EPSS score of less than 1% suggests that exploit attempts will be rare. The vulnerability is not listed in the CISA KEV catalog. Attacker must first obtain authenticated administrative access to inject the payload; the subsequent rendering requires a user to view the data. Because the flaw is bounded by current CSP controls, the risk to confidentiality, integrity, and availability is modest, but cosmetic and phishing implications can still be significant for exposed web interfaces.

Generated by OpenCVE AI on July 29, 2026 at 12:44 UTC.

Remediation

Vendor Solution

Upgrade to v26.2.0 or later.


Vendor Workaround

Use internal firewall features to limit access to the web management interface.


OpenCVE Recommended Actions

  • Upgrade Nozomi Networks CMC and Guardian to version 26.2.0 or later.
  • Configure internal firewalls to restrict access to the web management interface to trusted entities only.
  • Audit and remove any unused administrative accounts to reduce the attack surface.

Generated by OpenCVE AI on July 29, 2026 at 12:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data through multiple input vectors. When a victim views the affected data in the Diagram tab and Graph view, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.
Title HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0
First Time appeared Nozomi Networks
Nozomi Networks cmc
Nozomi Networks guardian
Weaknesses CWE-79
CPEs cpe:2.3:a:nozomi_networks:cmc:*:*:*:*:*:*:*:*
cpe:2.3:a:nozomi_networks:guardian:*:*:*:*:*:*:*:*
Vendors & Products Nozomi Networks
Nozomi Networks cmc
Nozomi Networks guardian
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Nozomi Networks Cmc Guardian
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-07-09T12:43:26.857Z

Reserved: 2026-03-10T16:14:03.265Z

Link: CVE-2026-31981

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')