Nozomi Networks Guardian and CMC Missing Authentication Vulnerability in SSH Keys Synchronization Endpoint

Vulnerability

A missing authentication vulnerability exists in the SSH keys synchronization endpoint of Nozomi Networks Guardian and CMC versions prior to 26.2.0. This vulnerability allows an unauthenticated attacker to send a request to the SSH keys synchronization endpoint and retrieve a list of users who have uploaded their public SSH keys, along with their associated groups and the uploaded keys.

Impact

Exploitation of this vulnerability allows for unauthorized access to user data, specifically the public SSH keys of users, their group affiliations, and the identities of users who have uploaded SSH keys.

Remediation

Users are advised to upgrade to version 26.2.0 or later. Additionally, internal firewall features can be used to limit access to the web management interface.

Added: Jul 9, 2026, 8:31 AM
Updated: Jul 9, 2026, 8:31 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.6
exploitability
7.0
remediation
7.9
relevance
9.2
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.