CVE-2026-33390 Details
Description
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.
A vulnerability allowing incorrect privilege assignment has been identified in Nozomi Networks Guardian and CMC versions prior to 26.2.0. This vulnerability arises from Arc sensors receiving command-line interface (CLI) permissions, which should not be granted. As a result, an authenticated user with limited privileges can exploit this issue by sending administrative CLI commands through the synchronization functionality. This exploitation can lead to unauthorized changes in device configuration and potentially disrupt the device's availability.
Users are advised to upgrade to Nozomi Networks Guardian or CMC version 26.2.0 or later. Additionally, review all enabled Arc sensors and remove or disable any untrusted ones.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-827968.html | siemens-SADP | |
| https://security.nozominetworks.com/NN-2026:13-01 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nozominetworks cmc | < 26.2.0 |
CPE
Remediation
| |
| nozominetworks guardian | < 26.2.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | CVE Modified | siemens-SADP |
| Jul 10, 2026 | Initial Analysis | [email protected] |
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |