CVE-2026-33922
Received Received - Intake

Path Traversal in Nozomi Networks Appliance Web Interface

Vulnerability report for CVE-2026-33922, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Nozomi Networks Inc.

Description

A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with administrative credentials for the web interface could submit an archive name containing traversal sequences and delete arbitrary files reachable by the Arc process, which runs with administrative privileges on the host.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nozomi_networks arc to 2.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in the Offline archives feature of the local web interface in Arc software. It allows a local user with admin credentials to submit an archive name with path traversal sequences, which can delete arbitrary files accessible to the Arc process running with admin privileges.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized file deletions or suspicious archive names in Arc's offline archives functionality. Review Arc's logs for administrative web interface access attempts with path traversal sequences like '../'. Check for Arc process activity involving file deletions outside its expected directories.

Impact Analysis

An attacker with admin access could delete critical system files, disrupt operations, or cause data loss. Since Arc runs with admin privileges, the impact includes potential system compromise or service disruption.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by allowing unauthorized file deletion on systems running affected Arc versions. Administrative privileges of the Arc process mean sensitive data or system files could be compromised, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Immediately upgrade Arc to version 2.7.0 or later. Review and rotate all administrative web interface credentials. If exposure to untrusted users is suspected, relaunch Arc's local web server to invalidate potential sessions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33922. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart