A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-40904

CVE-2025-40904: Nozomi Networks CMC XSS Vulnerability

CVE-2025-40904 is a stored XSS flaw in Nozomi Networks CMC's Smart Polling functionality that allows authenticated attackers to inject malicious HTML. This article covers technical details, affected versions, impact, and mitigation.

Published: May 21, 2026

CVE-2025-40904 Overview

CVE-2025-40904 is a stored HTML injection vulnerability affecting Nozomi Networks CMC and Guardian products. The flaw resides in the Smart Polling functionality and stems from improper validation of an input parameter [CWE-79]. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through the sync mechanism. When a victim subsequently views the affected remote strategy in Smart Polling, the injected HTML renders in their browser. The vendor reports that existing input validation and Content Security Policy (CSP) configuration prevent full Cross-Site Scripting (XSS) and direct information disclosure.

Critical Impact

An authenticated low-privilege attacker can inject persistent HTML into Smart Polling views, enabling phishing and potential open redirect attacks against operators of CMC and Guardian appliances.

Affected Products

  • Nozomi Networks CMC (Central Management Console)
  • Nozomi Networks Guardian
  • Smart Polling functionality across both products

Discovery Timeline

  • 2026-05-19 - CVE-2025-40904 published to NVD
  • 2026-05-19 - Last updated in NVD database

Technical Details for CVE-2025-40904

Vulnerability Analysis

The vulnerability is a stored HTML injection within the Smart Polling feature of Nozomi Networks CMC and Guardian. Smart Polling allows operators to define and synchronize remote strategies across managed sensors. The application accepts a parameter within remote strategy definitions without adequately sanitizing HTML markup before persisting and rendering it. When operators later open the affected strategy in the web interface, the stored markup is interpreted by the browser. The injection is persistent, meaning the payload triggers on every view of the affected resource until removed.

Root Cause

The root cause is improper neutralization of input during web page generation, classified under [CWE-79]. The vulnerable parameter passes HTML content through to the rendering layer without escaping reserved characters such as <, >, and quoting characters. The synchronization channel between CMC and Guardian propagates the unsanitized strategy data, expanding the blast radius from a single sensor to any node consuming the sync feed. Existing input validation and the deployed Content Security Policy reduce the impact by blocking inline script execution and external resource loads, which prevents full XSS but does not prevent rendering of arbitrary HTML structure.

Attack Vector

The attack requires an authenticated account with privileges to create or modify remote strategies in Smart Polling. The attacker crafts a remote strategy containing HTML elements such as anchor tags, iframes referencing same-origin content, or styled overlays. The strategy is then pushed through the sync mechanism to other appliances. When a victim with appropriate access views the strategy in the Smart Polling UI, the injected HTML renders in their authenticated session. Practical exploitation paths include displaying fake login prompts to harvest credentials and redirecting the victim to attacker-controlled domains through clickable elements.

No public proof-of-concept code has been published for this issue. Refer to the Nozomi Networks Security Advisory for vendor-supplied technical details.

Detection Methods for CVE-2025-40904

Indicators of Compromise

  • Remote strategy objects in CMC or Guardian containing HTML tags such as <a>, <iframe>, <img>, or <form> within text fields not intended to hold markup.
  • Audit log entries showing creation or modification of Smart Polling remote strategies by low-privilege accounts.
  • Outbound web requests from operator browsers to unexpected domains following Smart Polling page loads.

Detection Strategies

  • Query the configuration database or API for Smart Polling strategies and grep stored fields for angle brackets, href=, src=, or javascript: substrings.
  • Review web server access logs for repeated views of specific remote strategy IDs by privileged operators.
  • Correlate strategy sync events with subsequent authentication anomalies or unexpected redirects reported by operators.

Monitoring Recommendations

  • Enable verbose audit logging for Smart Polling configuration changes and ship logs to a centralized SIEM for retention and correlation.
  • Monitor browser-side CSP violation reports, which can surface attempted script execution blocked by the existing policy.
  • Alert on creation of remote strategies by non-administrative accounts and on bulk sync operations originating from low-privilege users.

How to Mitigate CVE-2025-40904

Immediate Actions Required

  • Apply the fixed versions of Nozomi Networks CMC and Guardian as identified in the Nozomi Networks Security Advisory NN-2026:7-01.
  • Audit existing Smart Polling remote strategies and remove any entries containing HTML markup in non-markup fields.
  • Review and restrict accounts authorized to create or modify remote strategies, removing the privilege from users who do not require it.

Patch Information

Nozomi Networks has published advisory NN-2026:7-01 describing fixed releases for CMC and Guardian. Customers should consult the advisory for the exact patched build numbers applicable to their deployment and follow the vendor's upgrade procedure. Both the CMC and any synchronized Guardian sensors must be updated to prevent reintroduction of malicious strategies through the sync channel.

Workarounds

  • Limit Smart Polling strategy authoring to fully trusted administrative accounts until patches are deployed.
  • Train operators to avoid clicking embedded links within Smart Polling strategy views and to validate URLs before authenticating.
  • Disable or restrict the sync of remote strategies between CMC and Guardian where the feature is not operationally required.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeXSS

  • Vendor/TechNozominetworks

  • SeverityMEDIUM

  • CVSS Score5.1

  • EPSS Probability0.03%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityLow
  • AvailabilityLow
  • CWE References
  • CWE-79
  • Vendor Resources
  • Nozomi Networks Security Advisory
  • Related CVEs
  • CVE-2025-40900: Nozomi Networks CMC XSS Vulnerability

  • CVE-2025-40901: Nozomi Networks CMC XSS Vulnerability

  • CVE-2025-40902: Nozomi Networks CMC XSS Vulnerability

  • CVE-2025-40903: Nozomi Networks CMC XSS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English