CVE-2026-33387
A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered into importing a malicious dashboard. When the victim views or imports the dashboard, the payload executes in their browser context, allowing the attacker to modify application data or disrupt application availability.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.18%
- CWE
- CWE-1336
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- Nozomi Networks Guardian
- Nozomi Networks CMC
Weakness type
Related vulnerabilities
- CVE-2026-19584 — Velociraptor VQL injection during notebook restore from backup
- CVE-2026-87021 — Tanium addressed an unauthorized code execution vulnerability in Comply.
- CVE-2026-75650 — Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
- CVE-2026-52762 — YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
- CVE-2026-46636 — Twig: Sandbox method allowlist bypass via `Markup` subclass
- CVE-2026-85654 — Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
- CVE-2026-13297 — Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
- CVE-2026-75036 — Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing