CVE-2026-76979: XML Injection vulnerability
Published Sep 23, 2026
·Updated
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.
Affected Software
2 affected components
Zohocorp ManageEngine OpManager<=12.8.709
Zohocorp Manageengine Firewall Analyzer<=12.8.709
Event History
Sep 23, 2026
CVE Published
via MITRE·12:22 PM
Data Sourced
via MITRE·12:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
ManageEngine OpManager and ManageEngine Firewall Analyzer versions 12.8.709 and below are affected, specifically in the Rule Tracking Compare Policies feature.
2
What access does an attacker need to exploit this issue?
The vector is network-accessible and the attack complexity is low, but the attacker must have low-level privileges. No user interaction is required.
3
What is the likely security impact?
The issue can lead to high confidentiality impact and affects the scope beyond the vulnerable component. The provided metrics indicate no integrity or availability impact.