Description
ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.
Published: 2026-09-23
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized path traversal
Action: Patch It
AI Analysis

Impact

ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 contain an authorization bypass that allows attackers to perform path traversal. This weakness permits reading or writing files outside the intended directory structure, potentially exposing sensitive configuration files or other confidential data. The primary consequence is unauthorized access to files, which can lead to information disclosure, configuration tampering or other integrity violations.

Affected Systems

The vulnerability affects ManageEngine OpManager and ManageEngine Network Configuration Manager from ZohoCorp. All releases prior to version 12.8.671 are impacted. Users of these products should verify their installed version and upgrade when possible.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity risk. EPSS is not available, so the likelihood of exploitation is uncertain. The vulnerability is not listed in CISA KEV. Based on the description, the attack vector is inferred to be feasible through the web interface or API without authentication, making it a potential remote exploitation path.

Generated by OpenCVE AI on September 23, 2026 at 13:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ManageEngine OpManager and Network Configuration Manager to version 12.8.671 or later.
  • If an upgrade cannot be performed immediately, restrict network access to the web or API endpoints that expose the vulnerable feature using firewall rules or access controls.
  • Guideline: review and disable any configuration options that allow directory traversal or direct file access outside the expected application directories.

Generated by OpenCVE AI on September 23, 2026 at 13:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.
Title Path Traversal Vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Network Configuration Manager
Zohocorp manageengine Opmanager
Weaknesses CWE-428
CPEs cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Network Configuration Manager
Zohocorp manageengine Opmanager
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Zohocorp Manageengine Network Configuration Manager Manageengine Opmanager
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-23T14:35:33.997Z

Reserved: 2026-07-10T06:45:45.143Z

Link: CVE-2026-15358

cve-icon Vulnrichment

Updated: 2026-09-23T14:35:13.855Z

cve-icon NVD

Status : Received

Published: 2026-09-23T12:17:05.630

Modified: 2026-09-23T15:17:11.383

Link: CVE-2026-15358

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T13:45:04Z

Weaknesses
  • CWE-428

    Unquoted Search Path or Element