CMC vulnerabilities
CVEs whose affected-version data names the CMC package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-33920Low· 3.5A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token
A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can trick a victim into unknowingly authenti…
CVE-2026-33391Medium· 5.4An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges
An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access cont…
CVE-2026-33389High· 7.5An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provi…
An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provi…
CVE-2026-33388High· 7.4An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges
An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available ent…
CVE-2026-33387Medium· 4.6A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter
A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload,…