CVE-2026-33920
- EPSS 0.1%
- Veröffentlicht 08.09.2026 13:57:54
- Zuletzt bearbeitet 08.09.2026 19:12:59
A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can trick a victim into unknowingly authenticating with t...
CVE-2026-33391
- EPSS 0.31%
- Veröffentlicht 08.09.2026 13:56:38
- Zuletzt bearbeitet 08.09.2026 19:12:59
An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the we...
CVE-2026-33389
- EPSS 0.12%
- Veröffentlicht 08.09.2026 13:55:16
- Zuletzt bearbeitet 08.09.2026 19:12:59
An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provided to enable...
CVE-2026-33388
- EPSS 0.28%
- Veröffentlicht 08.09.2026 13:53:16
- Zuletzt bearbeitet 08.09.2026 19:12:59
An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available entries in the C...
CVE-2026-33387
- EPSS 0.18%
- Veröffentlicht 08.09.2026 13:50:31
- Zuletzt bearbeitet 08.09.2026 19:12:59
A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim ...
CVE-2026-33390
- EPSS 0.22%
- Veröffentlicht 09.07.2026 07:23:30
- Zuletzt bearbeitet 11.08.2026 13:18:23
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, alt...
CVE-2026-31984
- EPSS 0.29%
- Veröffentlicht 09.07.2026 07:22:53
- Zuletzt bearbeitet 11.08.2026 13:18:14
A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into audit entries. An unauthenticated attacker can submit requests containing ...
CVE-2026-31983
- EPSS 0.24%
- Veröffentlicht 09.07.2026 07:22:44
- Zuletzt bearbeitet 11.08.2026 13:18:14
A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH k...
CVE-2026-31982
- EPSS 0.17%
- Veröffentlicht 09.07.2026 07:22:35
- Zuletzt bearbeitet 11.08.2026 13:18:14
An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison ...
CVE-2026-31981
- EPSS 0.15%
- Veröffentlicht 09.07.2026 07:22:21
- Zuletzt bearbeitet 11.08.2026 13:18:14
A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags int...