PT-2026-56728 · Unknown · Remote Collector

CVE-2026-31985

·

Published

2026-07-09

·

Updated

2026-07-09

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Remote Collector versions prior to 26.2.0
Description When configuring the upstream Guardian or CMC in the Remote Collector using the n2os-tui, the generated configuration disables TLS certificate verification without providing an option to enable it. This allows a malicious actor to execute a man-in-the-middle attack to intercept communications between the Remote Collector and the Guardian or CMC. Potential impacts include the theft of the sync token, server impersonation, disruption of data flow, or the injection of spoofed data, such as false asset information or vulnerabilities, into the Guardian or CMC.
Recommendations Update to version 26.2.0.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31985

Affected Products

Remote Collector