SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2026-31983

A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint.

MEDIUM 6.9EPSS 0.41%

Does this matter?

Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.

Description

A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys.

CVSS 4.0
6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.41% probability · 35th percentile
CISA KEV
Not listed
Weakness
CWE-306
Affected
nozominetworks/cmc · nozominetworks/guardian
Source
prodsec@nozominetworks.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.