Description
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.
Published: 2026-07-09
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect privilege assignment flaw allows Arc sensors to receive command‑line interface permissions that should only be granted to administrators. An authenticated user with limited privileges can use the synchronization feature to push administrative CLI commands, thereby altering device configuration and potentially disrupting availability. The flaw is a CWE‑266 weakness, where proper privilege levels are not enforced.

Affected Systems

The vulnerability affects Nozomi Networks CMC and Guardian products prior to version 26.2.0. Any deployment of these products that has not been upgraded is susceptible.

Risk and Exploitability

The CVSS score is 7.2, indicating a high severity. EPSS is under 1%, implying low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication and the presence of a user with limited privileges who can access the synchronization functionality; the attacker can then inject administrative CLI commands through that channel.

Generated by OpenCVE AI on July 29, 2026 at 12:42 UTC.

Remediation

Vendor Solution

Upgrade to v26.2.0 or later.


Vendor Workaround

Review all enabled sensors and disallow or delete untrusted ones.


OpenCVE Recommended Actions

  • Upgrade Nozomi Networks CMC and Guardian to version 26.2.0 or later
  • Review all enabled sensors and disallow or delete untrusted ones as per the official workaround
  • Apply least‑privilege access controls so that authenticated users cannot invoke synchronization functionality without proper authorization

Generated by OpenCVE AI on July 29, 2026 at 12:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.
Title Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0
First Time appeared Nozomi Networks
Nozomi Networks cmc
Nozomi Networks guardian
Weaknesses CWE-266
CPEs cpe:2.3:a:nozomi_networks:cmc:*:*:*:*:*:*:*:*
cpe:2.3:a:nozomi_networks:guardian:*:*:*:*:*:*:*:*
Vendors & Products Nozomi Networks
Nozomi Networks cmc
Nozomi Networks guardian
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Nozomi Networks Cmc Guardian
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-07-09T12:29:18.009Z

Reserved: 2026-03-19T11:28:43.172Z

Link: CVE-2026-33390

cve-icon Vulnrichment

Updated: 2026-07-09T12:26:10.011Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:45:03Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment