No advisories yet.
Solution
Upgrade to v26.3.0 or later.
Workaround
Users should always pay attention to phishing emails and untrusted links.
| Link | Providers |
|---|---|
| https://security.nozominetworks.com/NN-2026:18-01 |
|
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can trick a victim into unknowingly authenticating with the attacker's credentials. Any operation performed by the victim in this state is attributed to the attacker's account, compromising the integrity of the audit trail. | |
| Title | Cross-site request forgery in the Guardian/CMC login before 26.3.0 | |
| First Time appeared |
Nozomi Networks
Nozomi Networks cmc Nozomi Networks guardian |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:nozomi_networks:cmc:*:*:*:*:*:*:*:* cpe:2.3:a:nozomi_networks:guardian:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Nozomi Networks
Nozomi Networks cmc Nozomi Networks guardian |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2026-09-08T14:20:32.960Z
Reserved: 2026-03-24T16:06:11.950Z
Link: CVE-2026-33920
Updated: 2026-09-08T14:20:28.029Z
Status : Awaiting Analysis
Published: 2026-09-08T14:17:22.687
Modified: 2026-09-08T19:12:59.557
Link: CVE-2026-33920
No data.
OpenCVE Enrichment
Updated: 2026-09-08T17:30:05Z