Description
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.
Published: 2026-09-23
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: XML Injection potentially enabling remote code execution or data compromise
Action: Apply Patch
AI Analysis

Impact

An XML Injection flaw exists in the Rule Tracking Compare Policies feature of ManageEngine OpManager and Firewall Analyzer. The vulnerability allows an attacker to inject crafted XML content, which could lead to remote code execution or allow the attacker to manipulate data within the application. The weakness is classified as CWE-91, indicating insufficient validation of XML input.

Affected Systems

The affected products are ZohoCorp ManageEngine Firewall Analyzer and ZohoCorp ManageEngine OpManager. Versions 12.8.709 and earlier are vulnerable; any deployment using those or older releases is at risk.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified, but the lack of KEV listing suggests it is not a currently known exploited vulnerability. The likely attack vector is through authenticated or unauthenticated use of the web interface that exposes the Rule Tracking Compare Policies function. Exploitation would require the attacker to send malicious XML payloads to the target system.

Generated by OpenCVE AI on September 23, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ManageEngine OpManager and Firewall Analyzer to versions newer than 12.8.709 that contain the official fix.
  • If immediate upgrade is not feasible, disable or restrict access to the Rule Tracking Compare Policies feature to eliminate the injected input path.
  • Implement strict XML validation or whitelisting for user-supplied XML to reduce injection risk in the future.

Generated by OpenCVE AI on September 23, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.
Title XML Injection vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Firewall Analyzer
Zohocorp manageengine Opmanager
Weaknesses CWE-91
CPEs cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Firewall Analyzer
Zohocorp manageengine Opmanager
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Zohocorp Manageengine Firewall Analyzer Manageengine Opmanager
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-23T12:22:49.382Z

Reserved: 2026-08-20T06:00:53.815Z

Link: CVE-2026-76979

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T13:17:29.273

Modified: 2026-09-23T13:17:29.273

Link: CVE-2026-76979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:45:05Z

Weaknesses
  • CWE-91

    XML Injection (aka Blind XPath Injection)