Access Control Vulnerability in Threat Intelligence Functionality by Nozomi Networks
CVE-2025-40897

7.2HIGH

Key Information:

Vendor
CVE Published:
15 April 2026

What is CVE-2025-40897?

An access control flaw has been identified in the Threat Intelligence functionality of Nozomi Networks. This vulnerability arises from inadequate enforcement of access restrictions for users assigned view-only privileges. As a result, authenticated users possessing these limited privileges may execute unauthorized administrative actions, including altering rule configurations and impacting the availability of the functionality. This issue poses significant risks to the security posture of users relying on this feature for threat analysis.

Affected Version(s)

CMC 0 < 26.0.0

Guardian 0 < 26.0.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found by Andrea Palanca of Nozomi Networks Product Security team during an internal investigation.
.