CVE-2026-84787: Privilege Escalation vulnerability
Published Sep 23, 2026
·Updated
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
Affected Software
2 affected components
Zohocorp ManageEngine OpManager<=12.8.710
Zohocorp Manageengine Firewall Analyzer<=12.8.710
Event History
Sep 23, 2026
CVE Published
via MITRE·11:57 AM
Data Sourced
via MITRE·11:57 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
ZohoCorp ManageEngine OpManager and ManageEngine Firewall Analyzer version 12.8.710 and below are affected.
2
What access does an attacker need to exploit this issue?
An attacker must already be authenticated as a low-privilege user. They can then use Report Profile import to obtain Administrator privileges.
3
Does exploitation require user interaction or a complex attack path?
No user interaction is required, and the vulnerability has low attack complexity. The attack can be performed remotely over the network by an authenticated low-privilege user.