Description
An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforced for users with view-only privileges. An authenticated user with view-only privileges for the Threat Intelligence functionality can perform administrative actions on it, altering the rules configuration, and/or affecting their availability.
Problem types
CWE-863 Incorrect Authorization
Product status
Any version before 26.0.0
Any version before 26.0.0
Credits
This issue was found by Andrea Palanca of Nozomi Networks Product Security team during an internal investigation.
References
cert-portal.siemens.com/productcert/html/ssa-827968.html
security.nozominetworks.com/NN-2026:1-01