Junglewise Threat Intelligence

CVE-2026-31981: Nozomi Networks Guardian and CMC Stored HTML Injection

CVE-2026-31981 · Severity: medium · CVSS 5.9 · Published 2026-07-09

Technologies: Nozomi Networks Guardian, Nozomi Networks Central Management Console. Vendors: Nozomi Networks.

Executive brief

Nozomi Networks Guardian and CMC, which are used for industrial network monitoring and management, are affected by a security flaw in their web interface. An authorized administrator could inject malicious code into configuration data that, when viewed by other users, could lead to phishing or unauthorized website redirects. While existing security measures prevent full system takeover, the flaw could still be used to deceive operators or disrupt monitoring activities.

Technical details

A Stored HTML Injection vulnerability exists in the Diagram tab and Graph view of Nozomi Networks Guardian and CMC (N2OS) prior to version 26.2.0. The root cause is an insufficiently restrictive shared input validation function that fails to properly sanitize configuration data. An authenticated attacker with administrative privileges can inject malicious HTML tags via multiple input vectors. When a victim views the compromised data, the HTML is rendered in their browser, enabling phishing and open redirect attacks. Full Cross-Site Scripting (XSS) and data exfiltration are mitigated by existing input validation and a configured Content Security Policy (CSP). The issue is resolved in version 26.2.0.

Affected products

  • Nozomi Networks Guardian < 26.2.0
  • Nozomi Networks CMC < 26.2.0

Timeline

  • 2026-07-07: advisory: Initial advisory published by Nozomi Networks
  • 2026-07-09: disclosed: NVD publication date
  • 2026-07-07: patched: Version 26.2.0 released to address the vulnerability

References

Related threats