CVE-2026-33390

HIGH

Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0

Title source: cna
STIX 2.1

Description

An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0021
EPSS Percentile 11.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-266
Status published
Products (4)
Nozomi Networks/CMC < 26.2.0
Nozomi Networks/Guardian < 26.2.0
nozominetworks/cmc < 26.2.0
nozominetworks/guardian < 26.2.0
Published Jul 09, 2026
Tracked Since Jul 09, 2026