Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to v26.3.0 or later.
Vendor Workaround
Use internal firewall features to limit access to the web management interface.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://security.nozominetworks.com/NN-2026:16-01 |
|
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered into importing a malicious dashboard. When the victim views or imports the dashboard, the payload executes in their browser context, allowing the attacker to modify application data or disrupt application availability. | |
| Title | Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0 | |
| First Time appeared |
Nozomi Networks
Nozomi Networks cmc Nozomi Networks guardian |
|
| Weaknesses | CWE-1336 | |
| CPEs | cpe:2.3:a:nozomi_networks:cmc:*:*:*:*:*:*:*:* cpe:2.3:a:nozomi_networks:guardian:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Nozomi Networks
Nozomi Networks cmc Nozomi Networks guardian |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2026-09-08T14:19:01.400Z
Reserved: 2026-03-19T11:28:43.171Z
Link: CVE-2026-33387
Updated: 2026-09-08T14:18:56.125Z
Status : Received
Published: 2026-09-08T14:17:22.050
Modified: 2026-09-08T15:18:43.100
Link: CVE-2026-33387
No data.
OpenCVE Enrichment
No data.
-
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine