CVE-2026-84787
Awaiting Analysis Awaiting Analysis - Queue

Privilege Escalation in Zoho ManageEngine OpManager and Firewall Analyzer

Vulnerability report for CVE-2026-84787, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-24

Assigner: ManageEngine

Description

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
zoho manageengine_opmanager to 12.8.711 (exc)
zoho firewall_analyzer to 12.8.711 (exc)
zoho manageengine_opmanager_nexus to 12.9.135 (exc)
zoho manageengine_firewall_analyzer From 12.8.711 (inc)
zoho manageengine_opmanager_nexus From 12.9.135 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-250 The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-84787 is a high-severity privilege escalation vulnerability in ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below. An authenticated low-privilege user can exploit this by importing a malicious Report Profile to gain Administrator privileges.

Detection Guidance

To detect this vulnerability, check if your ManageEngine OpManager or Firewall Analyzer versions are below the fixed versions (12.8.711 for Firewall Analyzer, 12.9.125 for OpManager Nexus, or 12.9.135 for OpManager). Review imported Report Profiles for unauthorized privilege changes. No specific commands are provided in the resources.

Impact Analysis

This vulnerability allows an attacker with low-level access to escalate privileges to Administrator level, potentially gaining full control over the affected system. This could lead to unauthorized data access, system modifications, or further network compromise.

Compliance Impact

Privilege escalation vulnerabilities can violate compliance requirements by enabling unauthorized access to sensitive data, which may lead to data breaches. Organizations using affected versions must apply patches to maintain compliance with standards like GDPR and HIPAA.

Mitigation Strategies
  • Upgrade to Firewall Analyzer 12.8.711 or above, OpManager Nexus 12.9.125 or above, or OpManager versions 12.9.135 or above depending on your product.
  • If upgrading is not immediately possible, disable the Firewall Analyzer Plugin in OpManager or Enterprise Edition if enabled.
  • Apply the latest upgrade pack and build to your installations as soon as possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84787. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart