CVE-2026-33920
A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can trick a victim into unknowingly authenticating with the attacker's credentials. Any operation performed by the victim in this state is attributed to the attacker's account, compromising the integrity of the audit trail.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.10%
- CWE
- CWE-352
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- Nozomi Networks Guardian
- Nozomi Networks CMC
Weakness type
Related vulnerabilities
- CVE-2026-80380 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-84432 — Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog controller
- CVE-2026-88061 — career-ops: Local dashboard API accepted cross-origin and non-loopback requests, allowing unauthenticated command execution
- CVE-2026-88873 — WWBN AVideo Cross-Site Request Forgery via logArchive.json.php
- CVE-2026-88872 — AVideo CustomizeUser setPassword.json.php CSRF
- CVE-2026-88871 — WWBN AVideo CustomizeUser setSubscribers CSRF via GET
- CVE-2026-88870 — WWBN AVideo LoginControl PGP Key CSRF via GET Request
- CVE-2026-78083 — Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4