CVE-2026-15358
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in Zoho ManageEngine OpManager

Vulnerability report for CVE-2026-15358, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: ManageEngine

Description

ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-24
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
zoho manageengine_opmanager to 12.8.671 (exc)
zoho network_configuration_manager to 12.8.671 (exc)
zoho manageengine_opmanager_enterprise_edition to 12.8.671 (exc)
zoho manageengine_opmanager_nexus_enterprise_edition to 12.8.671 (exc)
zoho manageengine_network_configuration_manager_enterprise_edition to 12.8.671 (exc)
zoho manageengine_opmanager_msp to 12.8.671 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-428 The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-15358 is a high-severity unauthorized path traversal vulnerability in Zoho ManageEngine OpManager and Network Configuration Manager versions before 12.8.671. It allows attackers to access restricted files or directories without authentication by manipulating file paths.

Detection Guidance

To detect this vulnerability, check if your ManageEngine OpManager or Network Configuration Manager versions are below 12.8.671. Use commands like 'curl -v http://<target>/showImage.do?imagePath=../../../../etc/passwd' to test for path traversal. Verify installed versions with 'rpm -qa | grep -i manageengine' or check the web interface's version info.

Impact Analysis

This vulnerability could allow attackers to read sensitive files, access confidential data, or execute unauthorized actions on affected systems. It may lead to data breaches, system compromise, or further network infiltration if exploited.

Compliance Impact

This vulnerability could potentially expose sensitive data stored in affected systems, which may include personal or health information. Unauthorized path traversal may lead to data breaches, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Compliance risks include unauthorized access to sensitive data, potential data leaks, and failure to maintain adequate security controls.

Mitigation Strategies

Immediately upgrade affected ManageEngine products to the fixed versions released between July 10 and July 21, 2026. Download the latest upgrade packs from the official ManageEngine advisory links and apply them to OpManager Enterprise Edition, OpManager Nexus Enterprise Edition, Network Configuration Manager Enterprise Edition, and OpManager MSP.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15358. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart