← Back to CVE search

CVE-2026-33390

Arc sensors

Description

An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.

CVSS 8.1EPSS 0.21%Risk 0.83
View source
Published
2026-07-09 08:16:48
Affected versions
unknown
Type
Firmware
Last modified
2026-08-11 13:18:23
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H