High severity8.1NVD Advisory· Published Jul 9, 2026· Updated Aug 11, 2026
CVE-2026-33390
CVE-2026-33390
Description
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.
Affected products
3Patches
Vulnerability mechanics
References
2- security.nozominetworks.com/NN-2026:13-01nvdMitigationVendor Advisory
- cert-portal.siemens.com/productcert/html/ssa-827968.htmlnvd
News mentions
0No linked articles in our index yet.