Description
An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison the cached SAML redirection for other users who subsequently initiate SAML Single Sign-On, enabling phishing and credential-theft attacks, as well as disrupting SAML authentication for all affected users.
Published: 2026-07-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A user‑controlled redirect parameter in the SAML Single Sign‑On process is insufficiently validated, allowing an attacker to craft a request to the sign‑in endpoint that changes the cached redirect for other users. This open redirect can lure users to phishing sites, steal their credentials, or disrupt legitimate SAML authentication for all affected devices.

Affected Systems

Nozomi Networks CMC and Guardian devices running versions prior to 26.2.0 are affected.

Risk and Exploitability

The vulnerability can be triggered by unauthenticated attackers through the public SAML sign‑in interface, making it an application‑layer attack that does not require privileged credentials. Its CVSS score of 5.3 indicates moderate severity, while an EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis. The issue is not listed in the CISA KEV catalog. The likely attack vector is via the web interface that processes the SAML sign‑in request.

Generated by OpenCVE AI on July 29, 2026 at 12:43 UTC.

Remediation

Vendor Solution

Upgrade to v26.2.0 or later.


Vendor Workaround

Use internal firewall features to limit access to the web management interface.


OpenCVE Recommended Actions

  • Upgrade Nozomi Networks CMC or Guardian to v26.2.0 or later
  • Limit external access to the web management interface with internal firewall or VPN to block unauthenticated SAML requests
  • Disable or block SAML Single Sign‑On functionality until the patch is applied

Generated by OpenCVE AI on July 29, 2026 at 12:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison the cached SAML redirection for other users who subsequently initiate SAML Single Sign-On, enabling phishing and credential-theft attacks, as well as disrupting SAML authentication for all affected users.
Title Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0
First Time appeared Nozomi Networks
Nozomi Networks cmc
Nozomi Networks guardian
Weaknesses CWE-601
CPEs cpe:2.3:a:nozomi_networks:cmc:*:*:*:*:*:*:*:*
cpe:2.3:a:nozomi_networks:guardian:*:*:*:*:*:*:*:*
Vendors & Products Nozomi Networks
Nozomi Networks cmc
Nozomi Networks guardian
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Nozomi Networks Cmc Guardian
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-07-09T12:42:40.823Z

Reserved: 2026-03-10T16:14:03.266Z

Link: CVE-2026-31982

cve-icon Vulnrichment

Updated: 2026-07-09T12:41:40.431Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:45:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')