Description
An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available entries in the Credentials Manager. The actual credential values are not directly visible, but the user can delete entries or edit their properties. An attacker who deletes or edits an entry can disrupt authentication for dependent devices, and one who manipulates an entry's configuration may be able to indirectly obtain the credentials.
Published: 2026-09-08
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized privilege escalation affecting credential management
Action: Patch
AI Analysis

Impact

The vulnerability stems from insufficient validation of user privileges in the Credentials Manager. Users with limited authentication rights can view a restricted set of entries, yet they can delete or edit those entries. The actual credential values themselves are not exposed, but manipulation of entry properties can lead to indirect credential compromise or disruption of authentication for devices that rely on those credentials. This elevates a low‑privileged user to a position where they can degrade or compromise system integrity.

Affected Systems

Products impacted are Nozomi Networks CMC and Nozomi Networks Guardian. The advisory covers all versions of these products released before 26.3.0; users of any earlier version are therefore at risk.

Risk and Exploitability

The CVSS base score of 6.4 denotes a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting the likelihood of exploitation at present may be low. Nonetheless, an attacker who has already authenticated to the web interface—an access that can be gained remotely—could exploit this weakness to delete or alter credentials, potentially disabling authentication for dependent devices or acquiring credentials indirectly. The attack vector is likely remote authenticated access to the web management interface.

Generated by OpenCVE AI on September 8, 2026 at 16:11 UTC.

Remediation

Vendor Solution

Upgrade to v26.3.0 or later.


Vendor Workaround

Use internal firewall features to limit access to the web management interface.


OpenCVE Recommended Actions

  • Upgrade Nozomi Networks CMC and Guardian to version 26.3.0 or later.
  • Configure internal firewall rules to limit access to the web management interface.
  • Review all accounts with access to the web interface and remove unnecessary or unused ones.
  • Inspect existing entries in the Credentials Manager for unauthorized modifications.

Generated by OpenCVE AI on September 8, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available entries in the Credentials Manager. The actual credential values are not directly visible, but the user can delete entries or edit their properties. An attacker who deletes or edits an entry can disrupt authentication for dependent devices, and one who manipulates an entry's configuration may be able to indirectly obtain the credentials.
Title Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0
First Time appeared Nozomi Networks
Nozomi Networks cmc
Nozomi Networks guardian
Weaknesses CWE-863
CPEs cpe:2.3:a:nozomi_networks:cmc:*:*:*:*:*:*:*:*
cpe:2.3:a:nozomi_networks:guardian:*:*:*:*:*:*:*:*
Vendors & Products Nozomi Networks
Nozomi Networks cmc
Nozomi Networks guardian
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L'}

cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:L/SA:L'}


Subscriptions

Nozomi Networks Cmc Guardian
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-08T14:19:23.847Z

Reserved: 2026-03-19T11:28:43.172Z

Link: CVE-2026-33388

cve-icon Vulnrichment

Updated: 2026-09-08T14:19:19.058Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T14:17:22.210

Modified: 2026-09-08T19:12:59.557

Link: CVE-2026-33388

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T16:15:15Z

Weaknesses