{"id":"CVE-2026-33920","title":"A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token","summary":"A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can trick a victim into unknowingly authenti…","severity":"low","cvss":3.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-352"],"vendor":"Nozomi Networks","product":"Guardian","affected":["Guardian < 26.3.0","CMC < 26.3.0"],"published":"2026-09-08","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:12:59.557","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-33920","references":[{"url":"https://security.nozominetworks.com/NN-2026:18-01","label":"prodsec@nozominetworks.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T14:20:24.089951Z"},"ingestedAt":"2026-09-08T15:33:26.984Z","epss":0.00099,"epssPercentile":0.00928,"slug":"CVE-2026-33920","body":"## Overview\n\nA cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can trick a victim into unknowingly authenticating with the attacker's credentials. Any operation performed by the victim in this state is attributed to the attacker's account, compromising the integrity of the audit trail.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":19.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}