Junglewise Threat Intelligence

CVE-2026-33920: Nozomi Networks Guardian and CMC cross-site request forgery in login

CVE-2026-33920 · Severity: low · CVSS 3.5 · Published 2026-09-08

Technologies: Nozomi Networks Guardian, Nozomi Networks Central Management Console. Vendors: Nozomi Networks.

Executive brief

Guardian and CMC are network security monitoring and management platforms used by industrial and enterprise organizations. A CSRF vulnerability in the login functionality allows an attacker with a valid account to trick a victim into unknowingly authenticating as the attacker, causing all subsequent actions to be attributed to the attacker's account and compromising the audit trail.

Technical details

This is a cross-site request forgery (CWE-352) vulnerability in the login functionality of Guardian and CMC resulting from missing validation of anti-CSRF tokens for both standard and SAML-based authentication. The attack requires the attacker to have a valid account and the victim to interact with a malicious webpage while authenticated to the target system. An authenticated attacker can forge login requests that cause a victim to unknowingly assume the attacker's identity, leading to operation attribution, audit trail compromise, and potential unauthorized access. The vulnerability affects versions before 26.3.0; patched versions are available.

Affected products

  • Nozomi Networks Guardian before 26.3.0
  • Nozomi Networks CMC before 26.3.0

Timeline

  • 2026-09-08: disclosed

References

Related threats