Junglewise Threat Intelligence

CVE-2026-31983: Nozomi Networks Guardian and CMC missing authentication in SSH keys endpoint

CVE-2026-31983 · Severity: medium · CVSS 5.3 · Published 2026-07-09

Technologies: Nozomi Networks Guardian, Nozomi Networks Central Management Console. Vendors: Nozomi Networks.

Executive brief

Nozomi Networks Guardian and CMC, which are used for industrial network monitoring and management, contain a security flaw in their SSH key management system. An unauthorized person can access a specific web address to download a list of system users, their group memberships, and their public SSH keys. This information could be used by an attacker to map out the internal user structure and plan further targeted attacks against the organization's infrastructure.

Technical details

A Missing Authentication vulnerability (CWE-306) exists in the SSH keys synchronization endpoint of Nozomi Networks Guardian and CMC. The vulnerability is located in the web management interface and can be reached over the network without any prior authentication or user interaction. By sending a specially crafted request to this endpoint, an unauthenticated attacker can retrieve sensitive metadata including usernames, group associations, and public SSH keys. This information disclosure facilitates reconnaissance for further exploitation. The issue is resolved in version 26.2.0; as a workaround, users are advised to restrict access to the management interface using firewall rules.

Affected products

  • Nozomi Networks Guardian < 26.2.0
  • Nozomi Networks CMC < 26.2.0

Timeline

  • 2026-07-07: advisory: Initial internal advisory published by Nozomi Networks
  • 2026-07-09: disclosed: CVE published in NVD dataset

References

Related threats