CVE-2026-15358: Path Traversal Vulnerability
ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ZohoCorp ManageEngine OpManager and Network Configuration Managerto a version that resolves this vulnerability.Fixed in 12.8.671
Event History
Frequently Asked Questions
Which deployments are affected?
ZohoCorp ManageEngine OpManager and ManageEngine Network Configuration Manager versions before 12.8.671 are affected.
Does exploitation require authentication or user interaction?
No. The supplied vector indicates exploitation can be performed over the network with low attack complexity, without privileges or user interaction.
What is the potential impact of successful exploitation?
The supplied severity vector indicates high confidentiality impact, with no integrity or availability impact.
What version should be used to remediate the issue?
Upgrade affected OpManager or Network Configuration Manager installations to version 12.8.671 or later.