CVE-2026-31983

A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys.
References
Link Resource
https://security.nozominetworks.com/NN-2026:10-01 Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:*
cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:*

History

10 Jul 2026, 13:13

Type Values Removed Values Added
References () https://security.nozominetworks.com/NN-2026:10-01 - () https://security.nozominetworks.com/NN-2026:10-01 - Mitigation, Vendor Advisory
First Time Nozominetworks
Nozominetworks cmc
Nozominetworks guardian
CPE cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:*
cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:*

09 Jul 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-09 08:16

Updated : 2026-07-10 13:13


NVD link : CVE-2026-31983

Mitre link : CVE-2026-31983

CVE.ORG link : CVE-2026-31983


JSON object : View

Products Affected

nozominetworks

  • cmc
  • guardian
CWE
CWE-306

Missing Authentication for Critical Function