CVE-2026-75825: Authentication Bypass vulnerability
Published Sep 23, 2026
·Updated
ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.
Affected Software
1 affected component
Zohocorp ManageEngine OpManager<=12.8.710
Event History
Sep 23, 2026
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Affected deployments are ZohoCorp ManageEngine OpManager version 12.8.710 and below where the Application Manager Plugin is enabled.
2
What level of access does an attacker need?
The severity vector indicates network access, low attack complexity, no user interaction, and low privileges required. It also indicates high potential impact to confidentiality, integrity, and availability.