CVE-2026-33390

An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:*
cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-09 08:16

Updated : 2026-08-11 13:18


NVD link : CVE-2026-33390

Mitre link : CVE-2026-33390

CVE.ORG link : CVE-2026-33390


JSON object : View

Products Affected

nozominetworks

  • cmc
  • guardian
CWE
CWE-266

Incorrect Privilege Assignment