LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-33390

nozominetworks · cmc

Published
CVSS8.1
Severityhigh
WeaknessCWE-266
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Description

An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33390

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33390.