CVE-2026-15358
Awaiting Analysis
Awaiting Analysis - Queue
Path Traversal in Zoho ManageEngine OpManager
Vulnerability report for CVE-2026-15358, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-23
Last updated on: 2026-09-23
Assigner: ManageEngine
Description
Description
ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zoho | manageengine_opmanager | to 12.8.671 (exc) |
| zoho | network_configuration_manager | to 12.8.671 (exc) |
| zoho | manageengine_opmanager_enterprise_edition | to 12.8.671 (exc) |
| zoho | manageengine_opmanager_nexus_enterprise_edition | to 12.8.671 (exc) |
| zoho | manageengine_network_configuration_manager_enterprise_edition | to 12.8.671 (exc) |
| zoho | manageengine_opmanager_msp | to 12.8.671 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-428 | The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path. |