---
id: CVE-2026-33388
title: >-
  An access control vulnerability was discovered in the Credentials Manager
  functionality due to insufficient validation of user privileges
summary: >-
  An access control vulnerability was discovered in the Credentials Manager
  functionality due to insufficient validation of user privileges. A remote
  authenticated user with limited privileges can view a limited subset of the
  available ent…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L'
cwe:
  - CWE-863
vendor: Nozomi Networks
product: Guardian
affected:
  - Guardian < 26.3.0
  - CMC < 26.3.0
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:12:59.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33388'
references:
  - url: 'https://security.nozominetworks.com/NN-2026:19-01'
    label: prodsec@nozominetworks.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T14:19:12.408037Z'
ingestedAt: '2026-09-08T15:33:26.984Z'
epss: 0.00398
epssPercentile: 0.31145
---

## Overview

An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available entries in the Credentials Manager. The actual credential values are not directly visible, but the user can delete entries or edit their properties. An attacker who deletes or edits an entry can disrupt authentication for dependent devices, and one who manipulates an entry's configuration may be able to indirectly obtain the credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
