Junglewise Threat Intelligence

CVE-2026-33922: Nozomi Networks Arc path traversal in offline archives

CVE-2026-33922 · Severity: medium · CVSS 6 · Published 2026-08-11

Vendors: Nozomi Networks.

Executive brief

Nozomi Networks Arc is a software platform used for operational technology network visibility and threat detection. A path traversal vulnerability in the offline archives feature of the web interface allows an authenticated administrator to delete arbitrary files on the host system by submitting specially crafted archive names, potentially disrupting operations or compromising system integrity.

Technical details

This is a path traversal vulnerability (CWE-22) in Arc's offline archives functionality that stems from insufficient validation of archive name input parameters. An authenticated attacker with administrative credentials for the local web interface can exploit this by submitting archive names containing traversal sequences (e.g., "../../../"). The vulnerability allows deletion of arbitrary files that are accessible by the Arc process, which runs with administrative privileges. The attack is local-only and requires high privilege (administrative) authentication, limiting the attack surface. Patches are available in Arc v2.7.0 and later.

Affected products

  • Nozomi Networks Arc before v2.7.0

Timeline

  • 2026-08-11: disclosed

References