Description
A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys.
Published: 2026-07-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authentication flaw exists in the SSH keys synchronization endpoint of Nozomi Networks’ CMC Guardian products. Based on the description, it is inferred that an unauthenticated attacker who can reach the web‑management interface can send a request to this endpoint and retrieve a list of users who have uploaded public SSH keys, the groups those users belong to, and the public key data itself. The disclosed information includes usernames, group memberships, and key material, exposing sensitive configuration details.

Affected Systems

The vulnerability affects Nozomi Networks CMC and Guardian running a version earlier than 26.2.0. Deployments using these products should confirm their version and determine whether the endpoint is exposed to potential attackers.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, while the EPSS score of <1% suggests a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an attacker who can reach the web‑management interface; reaching the synchronization endpoint is sufficient to exploit the flaw due to lack of authentication.

Generated by OpenCVE AI on July 29, 2026 at 12:43 UTC.

Remediation

Vendor Solution

Upgrade to v26.2.0 or later.


Vendor Workaround

Use internal firewall features to limit access to the web management interface.


OpenCVE Recommended Actions

  • Upgrade to v26.2.0 or later.
  • Restrict external network access to the web‑management interface using internal firewall or network segmentation.
  • Use internal firewall features to limit access to the web management interface.

Generated by OpenCVE AI on July 29, 2026 at 12:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys.
Title Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0
First Time appeared Nozomi Networks
Nozomi Networks cmc
Nozomi Networks guardian
Weaknesses CWE-306
CPEs cpe:2.3:a:nozomi_networks:cmc:*:*:*:*:*:*:*:*
cpe:2.3:a:nozomi_networks:guardian:*:*:*:*:*:*:*:*
Vendors & Products Nozomi Networks
Nozomi Networks cmc
Nozomi Networks guardian
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Nozomi Networks Cmc Guardian
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-07-09T12:41:20.941Z

Reserved: 2026-03-10T16:14:03.266Z

Link: CVE-2026-31983

cve-icon Vulnrichment

Updated: 2026-07-09T12:41:17.695Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function