Description
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.
Published: 2026-09-23
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Command injection leading to remote code execution on the server
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker to inject arbitrary shell commands through the Diagnose Settings feature, resulting in full remote code execution on the underlying system. It is a classic command injection flaw identified as CWE-78, where untrusted input is incorporated into system command execution without proper sanitization.

Affected Systems

ZohoCorp’s ManageEngine Firewall Analyzer and ManageEngine OpManager versions 12.8.709 and earlier are susceptible to the flaw. The issue is documented by the vendor on the ManageEngine advisory page.

Risk and Exploitability

The CVSS score of 8.8 classifies the flaw as high severity, indicating a significant impact if successfully exploited. The EPSS value is not available, but the high CVSS suggests that a determined attacker may attempt exploitation. The vulnerability is not listed in the CISA KEV catalog, yet the lack of public exploitation does not diminish the risk. It is inferred that the attack vector is web‑based, requiring access to the Diagnose Settings function, which normally permits only users with administrative privileges. An attacker who obtains such privileges could execute arbitrary commands on the host.

Generated by OpenCVE AI on September 23, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ManageEngine Firewall Analyzer and OpManager to a version newer than 12.8.709, as released by ZohoCorp.
  • If an immediate upgrade is not possible, restrict or disable access to the Diagnose Settings feature so that only trusted administrators can use it, or remove the feature entirely if not needed.
  • Enable logging and monitor system logs for unexpected command execution or anomalous activity, and consider changing default passwords and strengthening authentication controls on the affected systems.

Generated by OpenCVE AI on September 23, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.
Title Command Injection vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Firewall Analyzer
Zohocorp manageengine Opmanager
Weaknesses CWE-78
CPEs cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Firewall Analyzer
Zohocorp manageengine Opmanager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zohocorp Manageengine Firewall Analyzer Manageengine Opmanager
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-23T12:28:35.789Z

Reserved: 2026-08-20T05:59:52.208Z

Link: CVE-2026-76978

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T13:17:29.153

Modified: 2026-09-23T13:17:29.153

Link: CVE-2026-76978

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T13:30:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')