---
id: CVE-2026-33391
title: >-
  An access control vulnerability was discovered in the Smart Polling
  configuration functionality due to insufficient validation of user privileges
summary: >-
  An access control vulnerability was discovered in the Smart Polling
  configuration functionality due to insufficient validation of user privileges.
  An authenticated user with limited privileges can remotely bypass the intended
  access cont…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-863
vendor: Nozomi Networks
product: Guardian
affected:
  - Guardian < 26.3.0
  - CMC < 26.3.0
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:12:59.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33391'
references:
  - url: 'https://security.nozominetworks.com/NN-2026:17-01'
    label: prodsec@nozominetworks.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T14:20:04.040705Z'
ingestedAt: '2026-09-08T15:33:26.984Z'
epss: 0.00341
epssPercentile: 0.24871
---

## Overview

An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and modify the Smart Polling discovery configuration. This allows the attacker to disrupt the visibility of assets in the monitored network.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
