CVE-2026-31985

When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verification, and no option was provided to enable it. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Remote Collector and the Guardian or CMC. This could result in theft of the sync token, impersonation of the server, injection of spoofed data (such as false asset information or vulnerabilities) into the Guardian or CMC, or disruption of the data flow between the Remote Collector and the Guardian or CMC.
Configurations

No configuration.

History

09 Jul 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-09 08:16

Updated : 2026-07-09 16:39


NVD link : CVE-2026-31985

Mitre link : CVE-2026-31985

CVE.ORG link : CVE-2026-31985


JSON object : View

Products Affected

No product.

CWE
CWE-671

Lack of Administrator Control over Security