CVE-2026-14913: SQL Injection vulnerability
Published Sep 23, 2026
·Updated
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports.
Affected Software
2 affected components
Zohocorp ManageEngine OpManager<=12.8.669
Zohocorp Manageengine Firewall Analyzer<=12.8.669
Event History
Sep 23, 2026
CVE Published
via MITRE·11:28 AM
Data Sourced
via MITRE·11:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require authentication or user interaction?
An attacker needs low-level privileges, so unauthenticated exploitation is not indicated. No user interaction is required.
2
What could a successful exploit allow an attacker to do?
The vulnerability is rated as having high impact on confidentiality, integrity, and availability. It is remotely reachable with low attack complexity.