Executive brief
Guardian and CMC are network monitoring and asset visibility products used by organizations to track and protect connected devices. A flaw in the Smart Polling configuration allows authenticated users with limited privileges to modify network discovery settings they should not be able to access, potentially hiding critical assets from monitoring and creating blind spots in network visibility.
Technical details
The vulnerability is an incorrect authorization (CWE-863) issue in the Smart Polling configuration functionality of Guardian/CMC versions before 26.3.0. An authenticated user with limited privileges can bypass access control checks in the web management interface due to insufficient validation of user permissions. The vulnerability requires network access and valid user credentials but no additional user interaction. An attacker can exploit this to modify Smart Polling discovery configuration, disrupting asset visibility within the monitored network. The fix is available in version 26.3.0 and later.
Affected products
- Nozomi Networks Guardian before 26.3.0
- Nozomi Networks CMC before 26.3.0
Timeline
- 2026-09-08: disclosed