CVE-2026-12370: Remote Code Execution Vulnerability
Published Sep 23, 2026
·Updated
ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.
Affected Software
3 affected components
Zohocorp ManageEngine OpManager<=12.8.667
Zohocorp Manageengine Netflow Analyzer<=12.8.667
Zohocorp Manageengine Network Configuration Manager<=12.8.667
Event History
Sep 23, 2026
CVE Published
via MITRE·11:20 AM
Data Sourced
via MITRE·11:20 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below are affected.
2
What level of access does an attacker need?
The vector indicates network-reachable exploitation with low attack complexity, but the attacker requires low-level privileges. No user interaction is required.
3
What is the potential impact of successful exploitation?
The Configlet-processing server-side template injection could lead to remote code execution. The listed impact includes high confidentiality impact and low integrity and availability impact.