Description
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
Published: 2026-09-23
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

The vulnerability allows an authenticated user with low privileges to gain Administrator rights by importing a Report Profile into ManageEngine OpManager or Firewall Analyzer. This is a classic case of improper privilege enforcement, classified as CWE-250. The attacker can thus perform actions normally reserved for administrators, such as modifying configurations, viewing sensitive data, or launching further attacks against the network.

Affected Systems

ZooCorp’s ManageEngine OpManager and Firewall Analyzer products, specifically versions 12.8.710 and older, are affected. Users of these applications should verify the installed version against the list of vulnerable releases.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated local or remote user who can use the Report Profile import feature. To exploit it, an attacker simply needs an account with read‑only or other low‑level privileges that still has access to the import function, which is then abused to elevate to full administrator status. The absence of mitigation restrictions makes exploitation straightforward for anyone who satisfies this minimal prerequisite.

Generated by OpenCVE AI on September 23, 2026 at 13:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-issued patch or upgrade to a version newer than 12.8.710.
  • Restrict the use of the Report Profile import feature to administrator accounts only.
  • Audit user roles and remove any unnecessary import privileges from low‑privilege users.

Generated by OpenCVE AI on September 23, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
Title Privilege Escalation vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Firewall Analyzer
Zohocorp manageengine Opmanager
Weaknesses CWE-250
CPEs cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Firewall Analyzer
Zohocorp manageengine Opmanager
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Zohocorp Manageengine Firewall Analyzer Manageengine Opmanager
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-23T12:42:00.390Z

Reserved: 2026-09-02T10:15:39.335Z

Link: CVE-2026-84787

cve-icon Vulnrichment

Updated: 2026-09-23T12:41:57.430Z

cve-icon NVD

Status : Received

Published: 2026-09-23T12:17:07.857

Modified: 2026-09-23T13:17:30.760

Link: CVE-2026-84787

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T13:30:05Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges