Executive brief
Guardian and CMC are network security monitoring and management platforms used by industrial and enterprise organizations. A CSRF vulnerability in the login functionality allows an attacker with a valid account to trick a victim into unknowingly authenticating as the attacker, causing all subsequent actions to be attributed to the attacker's account and compromising the audit trail.
Technical details
This is a cross-site request forgery (CWE-352) vulnerability in the login functionality of Guardian and CMC resulting from missing validation of anti-CSRF tokens for both standard and SAML-based authentication. The attack requires the attacker to have a valid account and the victim to interact with a malicious webpage while authenticated to the target system. An authenticated attacker can forge login requests that cause a victim to unknowingly assume the attacker's identity, leading to operation attribution, audit trail compromise, and potential unauthorized access. The vulnerability affects versions before 26.3.0; patched versions are available.
Affected products
- Nozomi Networks Guardian before 26.3.0
- Nozomi Networks CMC before 26.3.0
Timeline
- 2026-09-08: disclosed