CVE-2026-33390: Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arc sensors in Guardian/CMCto a version that resolves this vulnerability.Fixed in 26.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33390?
The severity of CVE-2026-33390 is rated as high with a score of 8.1.
How do I fix CVE-2026-33390?
To fix CVE-2026-33390, upgrade your Arc sensors to version 26.2.0 or later.
What are the implications of CVE-2026-33390?
CVE-2026-33390 allows authenticated users with limited privileges to execute administrative CLI commands, potentially altering device configuration.
What products are affected by CVE-2026-33390?
CVE-2026-33390 affects Arc sensors in Guardian/CMC versions prior to 26.2.0.
What type of vulnerability is CVE-2026-33390?
CVE-2026-33390 is classified as an Incorrect Privilege Assignment vulnerability.