CVE-2026-31983: Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0
A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Guardian/CMCto a version that resolves this vulnerability.Fixed in 26.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31983?
The severity of CVE-2026-31983 is medium with a score of 6.9.
How do I fix CVE-2026-31983?
To fix CVE-2026-31983, upgrade Guardian/CMC to version 26.2.0 or later where the vulnerability is resolved.
What can an attacker do with CVE-2026-31983?
An attacker can exploit CVE-2026-31983 to obtain a list of users' public SSH keys and their groups without authentication.
Which software is affected by CVE-2026-31983?
The software affected by CVE-2026-31983 includes Guardian/CMC SSH keys synchronization endpoint and Nozomi Networks CMC.
When was CVE-2026-31983 published?
CVE-2026-31983 was published on July 9, 2026.