A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys.
References
| Link | Resource |
|---|---|
| https://security.nozominetworks.com/NN-2026:10-01 | Mitigation Vendor Advisory |
| https://cert-portal.siemens.com/productcert/html/ssa-827968.html |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-09 08:16
Updated : 2026-08-11 13:18
NVD link : CVE-2026-31983
Mitre link : CVE-2026-31983
CVE.ORG link : CVE-2026-31983
JSON object : View
Products Affected
nozominetworks
- cmc
- guardian
CWE
CWE-306
Missing Authentication for Critical Function
