CVE-2026-33389
CVE-2026-33389 is a high-severity vulnerability with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-671.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v4: 5.3
- EPSS exploit prediction: 0% (4th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-671
- Published:
- Last modified:
Description
An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provided to enable it. A man-in-the-middle attacker positioned between a sensor and a polled device can, during a polling session, impersonate the device and intercept the communication, including the credentials used to access it. The captured credentials can then be replayed to authenticate against the device itself or against other devices sharing the same credentials, allowing the attacker to access and tamper with the device's data and to disrupt its operations.
Frequently asked questions
- What is CVE-2026-33389?
- An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provided to enable it. A man-in-the-middle attacker positioned between a sensor and a polled device can, during a polling session, impersonate the device and intercept the communication, including the credentials used to access it. The captured credentials can then be replayed to authenticate against the device itself or against other devices sharing the same credentials, allowing the attacker to access and tamper with the device's data and to disrupt its operations.
- How severe is CVE-2026-33389?
- CVE-2026-33389 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with high attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity low, and availability low.
- Is CVE-2026-33389 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (4th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-33389?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-33389 published?
- CVE-2026-33389 was published on 2026-09-08.
References
Other CWE-671 vulnerabilities
- CVE-2025-24024 — Critical (CVSS 9.1): Mjolnir is a moderation tool for Matrix. Mjolnir v1.9.0 responds to management commands from any room the bot is member…
- CVE-2018-13283 — High (CVSS 8.8): Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226…
- CVE-2026-31985 — High (CVSS 8.1): When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration…
- CVE-2023-20115 — Medium (CVSS 5.4): A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in…
- CVE-2022-29163 — Low (CVSS 3.5): Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions…