CVE-2026-33389: Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.0

Published Sep 8, 2026
·
Updated

An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provided to enable it. A man-in-the-middle attacker positioned between a sensor and a polled device can, during a polling session, impersonate the device and intercept the communication, including the credentials used to access it. The captured credentials can then be replayed to authenticate against the device itself or against other devices sharing the same credentials, allowing the attacker to access and tamper with the device's data and to disrupt its operations.

Affected Software

2 affected components
W3 Guardian/CMC<26.3.0
Arc<2.7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Arc to a version that resolves this vulnerability.

    Fixed in v2.7.0
  2. Upgrade

    Upgrade Guardian/CMC to a version that resolves this vulnerability.

    Fixed in v26.3.0

Event History

Sep 8, 2026
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Can certificate or host key validation be enabled as a workaround in affected releases?

No. Smart Polling in the affected releases did not provide an option to enable validation of the remote host identity.

2

What access does an attacker need to exploit this issue?

The attacker must be positioned between a sensor and the device being polled during a polling session, allowing them to perform a man-in-the-middle attack. No prior privileges are required, but user interaction is involved.

3

What is the impact if polling credentials are intercepted?

Captured credentials can be replayed against the polled device or other devices that share those credentials. This can allow an attacker to access and alter device data and disrupt device operations.

4

Which versions require remediation?

Guardian/CMC releases before 26.3.0 and Arc releases before v2.7.0 are affected when using Smart Polling.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203