CVE-2026-33391

MEDIUMCVSS 5.4/10

Last modified

CVE-2026-33391 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration.

Description

An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
Nozomi NetworksGuardian< 26.3.0
Nozomi NetworksCMC< 26.3.0

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-33391?
An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network.
How severe is CVE-2026-33391?
CVE-2026-33391 has a CVSS score of 5.4/10 (MEDIUM severity).
How do I fix CVE-2026-33391?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-33391?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST