CVE-2026-33388
Awaiting Analysis Awaiting Analysis - Queue

Access Control Flaw in Credentials Manager

Vulnerability report for CVE-2026-33388, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: Nozomi Networks Inc.

Description

An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available entries in the Credentials Manager. The actual credential values are not directly visible, but the user can delete entries or edit their properties. An attacker who deletes or edits an entry can disrupt authentication for dependent devices, and one who manipulates an entry's configuration may be able to indirectly obtain the credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an access control vulnerability in the Credentials Manager where insufficient validation of user privileges allows remote authenticated users with limited access to view some entries, delete them, or edit their properties. While actual credential values are not directly visible, attackers can disrupt authentication for dependent devices or indirectly obtain credentials by manipulating entry configurations.

Impact Analysis

An attacker could delete or modify credential entries, causing authentication failures for systems relying on those credentials. This may lead to service disruptions or unauthorized access if configuration changes expose credential values indirectly.

Mitigation Strategies

Implement strict access controls to ensure only authorized users can modify credentials. Review and restrict user privileges in the Credentials Manager. Monitor for unauthorized deletions or edits of credential entries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33388. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart