CVE-2026-33920
Awaiting Analysis Awaiting Analysis - Queue

Cross-Site Request Forgery in Login Functionality

Vulnerability report for CVE-2026-33920, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: Nozomi Networks Inc.

Description

A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can trick a victim into unknowingly authenticating with the attacker's credentials. Any operation performed by the victim in this state is attributed to the attacker's account, compromising the integrity of the audit trail.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a cross-site request forgery (CSRF) vulnerability in the login functionality, including SAML authentication. It occurs because the application fails to validate anti-CSRF tokens properly. An attacker with a valid account can trick a victim into authenticating with the attacker's credentials without their knowledge.

Impact Analysis

If exploited, this vulnerability allows an attacker to perform actions on your behalf without your consent. Any operations you perform while under this attack are recorded as the attacker's actions, which can lead to unauthorized changes, data breaches, or compromised audit trails.

Compliance Impact

This vulnerability can severely impact compliance by compromising the integrity of audit trails. GDPR requires accurate logging for accountability, while HIPAA mandates secure and reliable record-keeping. Exploits could lead to unauthorized access or actions, violating these regulations and potentially resulting in legal penalties.

Mitigation Strategies

Enable and validate anti-CSRF token checks in login functionality for both standard and SAML authentication methods. Review audit logs for suspicious activity where victim operations are attributed to attacker accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33920. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart