Executive brief
Guardian and CMC are network monitoring and management platforms used to oversee industrial control systems and IT infrastructure. A template injection flaw in the Dashboards feature allows an authenticated attacker to inject malicious code that executes in users' browsers when they view a poisoned dashboard, potentially enabling data modification or service disruption.
Technical details
A template injection vulnerability (CWE-1336) exists in the Dashboards functionality due to improper sanitization of input parameters. An authenticated user with sufficient privileges can craft a malicious dashboard payload or trick a victim into importing one. When the victim views or imports the dashboard, the unsanitized template code executes in the browser context, allowing the attacker to modify application data or disrupt availability. The vulnerability requires authentication and user interaction (viewing or importing the dashboard). Patches are available in Guardian/CMC version 26.3.0 and later.
Affected products
- Nozomi Networks Guardian before 26.3.0
- Nozomi Networks CMC before 26.3.0
Timeline
- 2026-09-08: disclosed: CVE-2026-33387 published
- 2026-09-08: patched: Fix available in Guardian/CMC v26.3.0 and later