Description
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.
Published: 2026-09-23
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unauthorized configuration changes via broken access control
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a broken access control flaw (CWE‑639) in ManageEngine OpManager and Firewall Analyzer that permits an authenticated user with low privileges to alter change‑management report schedule settings for firewalls that are outside their assigned scope. This capability can distort or delete reporting data, potentially masking malicious activity or affecting compliance.

Affected Systems

Affected products include Zohocorp's ManageEngine Firewall Analyzer and OpManager. Versions 12.8.710 and earlier are impacted. The flaw resides in the web‑based administration consoles of both applications, as identified in the vendor advisory.

Risk and Exploitability

The CVSS score of 7.1 indicates a high potential for damage, and because only a low‑privilege authenticated account is required, a compromised user could exploit the flaw. No EPSS data is available, and the vulnerability is not listed in KEV, suggesting that large‑scale exploitation has not yet been observed but remains possible. Based on the description, it is inferred that attackers would most likely trigger the issue via the web UI, submitting crafted requests that modify report schedules; until a patch is applied, the risk is moderate to high.

Generated by OpenCVE AI on September 23, 2026 at 14:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a ManageEngine release newer than 12.8.710 that includes the fix for the broken access control flaw.
  • If an update is not immediately available, restrict low‑privilege users from modifying change‑management report schedules and enforce strict role‑based access controls in the application configuration.
  • Monitor audit logs for unauthorized changes to report schedules and review user permissions regularly.
  • Ensure the firewall monitoring interface is protected behind VPN or internal networks to limit exposed attack surface.

Generated by OpenCVE AI on September 23, 2026 at 14:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.
Title Broken Access Control vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Firewall Analyzer
Zohocorp manageengine Opmanager
Weaknesses CWE-639
CPEs cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Firewall Analyzer
Zohocorp manageengine Opmanager
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Zohocorp Manageengine Firewall Analyzer Manageengine Opmanager
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-23T14:44:07.748Z

Reserved: 2026-09-02T10:18:28.363Z

Link: CVE-2026-84791

cve-icon Vulnrichment

Updated: 2026-09-23T14:42:50.325Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-23T12:17:08.110

Modified: 2026-09-23T18:17:31.543

Link: CVE-2026-84791

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:00:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key