PT-2026-56729 · Unknown · Guardian/Cmc

CVE-2026-33390

·

Published

2026-07-09

·

Updated

2026-07-09

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Guardian/CMC versions prior to 26.2.0
Description An Incorrect Privilege Assignment issue exists in the synchronization functionality where Arc sensors are granted CLI permissions. This allows an authenticated user with limited privileges to push administrative CLI commands through the sync process, which can lead to unauthorized alterations of the device configuration or impact its availability.
Recommendations Update Guardian/CMC to version 26.2.0 or later.

Fix

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33390

Affected Products

Guardian/Cmc