A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys.
References
| Link | Resource |
|---|---|
| https://security.nozominetworks.com/NN-2026:10-01 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
10 Jul 2026, 13:13
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://security.nozominetworks.com/NN-2026:10-01 - Mitigation, Vendor Advisory | |
| First Time |
Nozominetworks
Nozominetworks cmc Nozominetworks guardian |
|
| CPE | cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:* cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:* |
09 Jul 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-09 08:16
Updated : 2026-07-10 13:13
NVD link : CVE-2026-31983
Mitre link : CVE-2026-31983
CVE.ORG link : CVE-2026-31983
JSON object : View
Products Affected
nozominetworks
- cmc
- guardian
CWE
CWE-306
Missing Authentication for Critical Function
