Junglewise Threat Intelligence

CVE-2026-33391: Nozomi Guardian/CMC incorrect authorization in Smart Polling configuration

CVE-2026-33391 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Technologies: Nozomi Networks Guardian, Nozomi Networks Central Management Console. Vendors: Nozomi Networks.

Executive brief

Guardian and CMC are network monitoring and asset visibility products used by organizations to track and protect connected devices. A flaw in the Smart Polling configuration allows authenticated users with limited privileges to modify network discovery settings they should not be able to access, potentially hiding critical assets from monitoring and creating blind spots in network visibility.

Technical details

The vulnerability is an incorrect authorization (CWE-863) issue in the Smart Polling configuration functionality of Guardian/CMC versions before 26.3.0. An authenticated user with limited privileges can bypass access control checks in the web management interface due to insufficient validation of user permissions. The vulnerability requires network access and valid user credentials but no additional user interaction. An attacker can exploit this to modify Smart Polling discovery configuration, disrupting asset visibility within the monitored network. The fix is available in version 26.3.0 and later.

Affected products

  • Nozomi Networks Guardian before 26.3.0
  • Nozomi Networks CMC before 26.3.0

Timeline

  • 2026-09-08: disclosed

References

Related threats