Executive brief
A vulnerability in the reporting feature of Nozomi Networks Guardian and CMC appliances could allow an authorized user to execute malicious code in another user's browser. By creating or tricking a user into importing a specially crafted report template, an attacker can modify application data or disrupt the availability of the management interface. While existing security controls prevent full data theft, the flaw can still be used to interfere with normal operations.
Technical details
An Angular template injection vulnerability (CWE-1336) exists in the Reports functionality of Nozomi Networks Guardian and CMC due to improper validation of input parameters. An authenticated attacker with report privileges can define a malicious report containing an Angular template payload, or socially engineer a victim into importing a malicious template. When the victim views or imports the report, the template executes in their browser context. While Content Security Policy (CSP) and existing input validation prevent full Cross-Site Scripting (XSS) and direct information disclosure, an attacker can still modify application data or disrupt availability. The issue is fixed in version 26.1.0.
Affected products
- Nozomi Networks Guardian < 26.1.0
- Nozomi Networks CMC < 26.1.0
Timeline
- 2026-05-19: disclosed
- 2026-05-19: patched: Fixed in version 26.1.0
- 2026-05-19: advisory