Junglewise Threat Intelligence

CVE-2026-33388: Nozomi Networks Guardian/CMC incorrect authorization in Credentials Manager

CVE-2026-33388 · Severity: high · CVSS 7.4 · Published 2026-09-08

Technologies: Nozomi Networks Guardian, Nozomi Networks Central Management Console. Vendors: Nozomi Networks.

Executive brief

Nozomi Networks Guardian and CMC are network monitoring and management platforms used to oversee industrial control systems and critical infrastructure. An authenticated attacker with low privileges can view, delete, or modify credential entries managed by these systems, potentially disrupting authentication for dependent devices or extracting sensitive credentials. This could lead to unauthorized access to monitored systems or operational disruptions.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the Credentials Manager functionality of Nozomi Networks Guardian and CMC versions prior to 26.3.0. The vulnerability stems from insufficient validation of user privileges when accessing credential entries. An authenticated remote attacker with limited privileges can enumerate, delete, and edit credential entries, though the actual plaintext credential values are not directly exposed. An attacker manipulating or deleting entries can disrupt authentication for dependent devices or indirectly obtain credentials through configuration manipulation. The vulnerability requires network access and valid user authentication; no user interaction is required. Patches are available in Guardian/CMC version 26.3.0 and later.

Affected products

  • Nozomi Networks Guardian before 26.3.0
  • Nozomi Networks CMC before 26.3.0

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Guardian/CMC version 26.3.0 and later

References

Related threats