Description
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope.
Published: 2026-09-23
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unauthorized creation of alert notifications for firewalls outside an authenticated user's assigned scope
Action: Apply Patch
AI Analysis

Impact

An authenticated user with low privileges can exploit a broken access control flaw to create alert notifications for firewalls not within their assigned scope. This grants the user elevated visibility and influence over firewall alert mechanisms, potentially enabling privacy violations, alert fatigue, or discovery of network boundaries.

Affected Systems

The vulnerability affects ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and earlier. Updated releases that remove the flaw are available for both products.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity impact. EPSS information is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that while the flaw is serious, public exploitation evidence is not yet documented. The attack requires prior authentication, so the most plausible vector involves a legitimate, low‑privileged account being used to trigger the unauthorized alert creation.

Generated by OpenCVE AI on September 23, 2026 at 13:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest version of ManageEngine OpManager and Firewall Analyzer (12.8.711 or higher) which fixes the broken access control issue.
  • If an immediate update is not possible, restrict the affected user accounts to only the firewall scopes they should manage and deny permissions to create alerts on other firewalls.
  • After applying the update or restriction, monitor for unauthorized alert creation events and review firewall alert logs for anomalous entries.

Generated by OpenCVE AI on September 23, 2026 at 13:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope.
Title Broken Access Control vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Firewall Analyzer
Zohocorp manageengine Opmanager
Weaknesses CWE-639
CPEs cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Firewall Analyzer
Zohocorp manageengine Opmanager
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Zohocorp Manageengine Firewall Analyzer Manageengine Opmanager
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-23T12:43:29.855Z

Reserved: 2026-09-02T10:16:27.673Z

Link: CVE-2026-84789

cve-icon Vulnrichment

Updated: 2026-09-23T12:42:49.461Z

cve-icon NVD

Status : Received

Published: 2026-09-23T12:17:07.983

Modified: 2026-09-23T13:17:30.873

Link: CVE-2026-84789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T13:45:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key