Description
ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.
Published: 2026-09-23
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises because an authentication check is missing when the Application Manager Plugin is enabled, allowing attackers to craft requests that bypass authentication and gain unauthorized access to the OpManager management interface. This flaw is classified as CWE-306, giving an adversary the ability to perform privileged actions such as modifying monitoring configurations or extracting sensitive data.

Affected Systems

Zohocorp’s ManageEngine OpManager, versions 12.8.710 and earlier, are impacted when the Application Manager Plugin is active. Any deployment of these versions with the plugin enabled is subject to the bypass, regardless of the underlying operating system. Upgrading to a version newer than 12.8.710 eliminates the issue.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability, and while the EPSS score is not available, the absence of a KEV listing suggests no publicly known exploits yet. The likely attack vector is remote; an attacker who can reach the OpManager instance could trigger the bypass over HTTP or HTTPS without valid credentials, potentially enabling full system compromise.

Generated by OpenCVE AI on September 23, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor patch or upgrade to a version newer than 12.8.710.
  • Disable the Application Manager Plugin if it is not required for business operations.
  • Enforce strong authentication and monitor access logs for suspicious activity.

Generated by OpenCVE AI on September 23, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.
Title Authentication Bypass vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Opmanager
Weaknesses CWE-306
CPEs cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Opmanager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zohocorp Manageengine Opmanager
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-23T12:35:00.864Z

Reserved: 2026-08-18T10:50:37.064Z

Link: CVE-2026-75825

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T13:17:28.557

Modified: 2026-09-23T13:17:28.557

Link: CVE-2026-75825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:00:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function