CVE-2026-31981: Stored HTML Injection in Nozomi Networks CMC and Guardian
A stored HTML injection vulnerability in Nozomi Networks CMC and Guardian allows authenticated administrators to inject malicious HTML into configuration data. When other users view the affected data in the Diagram tab or Graph view, the injected HTML renders in their browsers. This can be used to conduct phishing attacks or redirect users to malicious sites. The vulnerability requires administrative access to exploit and user interaction (viewing the affected data) to trigger, limiting its scope but still warranting remediation in environments where admin accounts may be compromised or insider threats are a concern.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.9 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
- Weaknesses (CWE)
- CWE-79
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-07-09 / 2026-08-11
NVD description (verbatim)
A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data through multiple input vectors. When a victim views the affected data in the Diagram tab and Graph view, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-31981 is a stored cross-site scripting (XSS) vulnerability rooted in insufficient input validation in a shared validation function used by the Diagram tab and Graph view components in Nozomi Networks CMC and Guardian. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data through multiple input vectors. The injected content persists in the configuration and renders client-side when viewed by other users. The vulnerability is partially mitigated by existing Content Security Policy (CSP) configuration and additional input validation that prevent full XSS exploitation and direct information disclosure, but stored HTML injection remains viable for attacks like phishing and open redirects.
Business impact
The primary business risk is credential compromise through phishing attacks embedded in legitimate-looking configuration views. An adversary with administrative access (either through compromise or insider threat) can inject malicious HTML to deceive other users into disclosing credentials or visiting attacker-controlled sites. This could lead to lateral movement within the network monitoring infrastructure, unauthorized changes to monitoring policies, or disruption of visibility into critical operational technology environments. The medium CVSS score reflects the requirement for high-privilege access and user interaction, but the damage potential in OT/network security contexts warrants prompt remediation.
Affected systems
Nozomi Networks CMC and Guardian are affected. Both products use the same insufficiently restrictive input validation function that fails to properly sanitize HTML in the Diagram tab and Graph view. Organizations deploying these network security and monitoring solutions should assess their administrative access controls and user awareness to determine exposure.
Exploitability
Exploitation requires authenticated administrative privileges, making it unsuitable for unauthenticated attacks but relevant for insider threat and account compromise scenarios. The attack requires a victim to view the poisoned configuration data in the Diagram tab or Graph view, introducing a user interaction requirement. Existing CSP policies and additional validation prevent escalation to full XSS with script execution or data exfiltration, narrowing the attack surface to HTML-based phishing and redirect attacks. Overall exploitability is constrained but not negligible in high-risk environments.
Remediation
Contact Nozomi Networks for patched versions of CMC and Guardian that strengthen input validation in the shared validation function. Interim mitigations include restricting administrative access to only trusted users, monitoring configuration change logs for suspicious HTML patterns, and educating users to verify URLs and requests before clicking links in configuration views. Verify against the vendor advisory for specific patched version numbers and deployment guidance.
Patch guidance
Patches are available from Nozomi Networks for both CMC and Guardian products. Consult the vendor advisory and security bulletins for specific patch version numbers and deployment procedures. Test patches in a non-production environment first, as these products are critical to network monitoring and visibility. Coordinate patching with change control processes to minimize disruption to OT visibility.
Detection guidance
Monitor N2OS configuration files and database logs for HTML tags (e.g., <script>, <img>, <iframe>, <a>) in fields not expected to contain markup, particularly in Diagram and Graph view configuration data. Web application firewalls and endpoint detection systems should flag unusual HTML injection patterns in configuration submissions. Review administrative user activity logs for changes to configuration data, and correlate with phishing complaints or suspicious user behavior. Implement integrity checks or hashing of configuration baselines to detect unauthorized modifications.
Why prioritize this
Although the CVSS score is medium (5.9), prioritization should account for the OT/network security context. Nozomi products are often deployed as critical visibility tools in industrial and operational technology environments. A compromise of administrative accounts or insider threats could weaponize this vulnerability to deceive operators or security teams. Organizations with mature admin access controls and security awareness can deprioritize slightly; those with weaker access governance should treat this as higher priority. The lack of current exploitation in the wild (no KEV listing) provides a window for orderly patching.
Risk score, explained
The CVSS 3.1 score of 5.9 (MEDIUM) reflects the following factors: Network-accessible attack vector, low attack complexity, high privileges required, and requirement for user interaction. Confidentiality, integrity, and availability impacts are all rated as low because CSP and additional input validation prevent direct information disclosure and script execution. However, the impact is rated as 'Scope Changed' (affecting resources beyond the vulnerable component) because phishing and redirect attacks can affect users outside the immediate application. The score appropriately penalizes the high privilege requirement while recognizing the real risk of HTML injection for social engineering.
Frequently asked questions
Can this vulnerability be exploited without administrative access?
No. The vulnerability requires authenticated access with administrative privileges to inject malicious HTML into configuration data. This significantly limits the attack surface to insider threats or compromised admin accounts.
Will the existing Content Security Policy prevent all attacks?
CSP and additional input validation prevent full XSS exploitation with script execution and direct data exfiltration. However, stored HTML injection for phishing links and open redirects is still possible and can bypass these mitigations.
How quickly should we patch this?
Patch timeframe depends on your admin access controls and user awareness. Environments with strong privileged access management and security training can use a standard maintenance window. Those with weaker controls or high insider threat risk should prioritize faster patching. Consult your vendor for patch availability and testing procedures.
What monitoring can detect if this has been exploited in our environment?
Look for HTML tags in configuration data fields, unusual configuration change logs, and correlation with phishing reports or suspicious user behavior. Implement configuration baseline integrity checks and log all administrative changes with full audit trails.
This analysis is based on the CVE record and vendor disclosures current as of the publication and modification dates. Patch version numbers, KEV status, and vendor timelines are subject to change; verify against official Nozomi Networks security advisories and product documentation. This vulnerability has not been observed in the CISA KEV catalog as of this writing. No exploit code or weaponized proof-of-concept details are provided. Organizations should conduct their own risk assessments tailored to their specific deployments, administrative practices, and threat models. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2016-20070MEDIUMPrivilege Escalation & Stored XSS in WordPress Booking Calendar Contact Form 1.0.23
- CVE-2018-25384MEDIUMStored XSS in Wikidforum 2.20 Allows Authenticated Attackers to Inject Malicious Scripts
- CVE-2019-25731MEDIUMStored XSS in Zuz Music 2.1 Contact Form
- CVE-2019-25737MEDIUMStored XSS in Live Chat Unlimited 2.8.3 – Admin Session Compromise
- CVE-2019-25739MEDIUMGigToDo 1.3 Stored XSS Vulnerability in Proposal Descriptions
- CVE-2019-25742MEDIUMStored XSS in Zoner Real Estate WordPress Theme 4.1.1 – Admin Account Compromise Risk
- CVE-2019-25743MEDIUMWordPress Soliloquy Lite 2.5.6 Stored XSS Vulnerability
- CVE-2019-25744MEDIUMWordPress Popup Builder 3.49 Stored XSS Vulnerability – Exploit Prevention & Patch Guide