CVE-2026-31983 Details
Description
A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys.
A missing authentication vulnerability exists in the SSH keys synchronization endpoint of Nozomi Networks Guardian and CMC versions prior to 26.2.0. This vulnerability allows an unauthenticated attacker to send a request to the SSH keys synchronization endpoint and retrieve a list of users who have uploaded their public SSH keys, along with their associated groups and the uploaded keys.
Users are advised to upgrade to version 26.2.0 or later. Additionally, internal firewall features can be used to limit access to the web management interface.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-827968.html | siemens-SADP | |
| https://security.nozominetworks.com/NN-2026:10-01 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nozominetworks cmc | < 26.2.0 |
CPE
Remediation
| |
| nozominetworks guardian | < 26.2.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | CVE Modified | siemens-SADP |
| Jul 10, 2026 | Initial Analysis | [email protected] |
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |