PT-2026-56728 · Unknown · Remote Collector
CVE-2026-31985
·
Published
2026-07-09
·
Updated
2026-07-09
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Remote Collector versions prior to 26.2.0
Description
When configuring the upstream Guardian or CMC in the Remote Collector using the n2os-tui, the generated configuration disables TLS certificate verification without providing an option to enable it. This allows a malicious actor to execute a man-in-the-middle attack to intercept communications between the Remote Collector and the Guardian or CMC. Potential impacts include the theft of the sync token, server impersonation, disruption of data flow, or the injection of spoofed data, such as false asset information or vulnerabilities, into the Guardian or CMC.
Recommendations
Update to version 26.2.0.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Remote Collector