AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-33390

HIGH · CVSS 8.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

An Incorrect Privilege Assignment vulnerability allows authenticated users with limited privileges to execute administrative CLI commands via the synchronization functionality of Arc sensors, potentially compromising device configuration and availability. Organizations utilizing affected Arc sensor products should prioritize remediation to prevent unauthorized access and maintain system integrity.

CVE
CVE-2026-33390
Severity
HIGH
CVSS
8.1
EPSS
0.21%

Original NVD Description

An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)