CVE-2026-87109: Ops Manager Sensitive MFA Enrollment Information Exposure in User Listings
An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through user-listing endpoints while that member's enrollment is unconfirmed. This results in disclosure of secret authentication material to another member of the same organization or project.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated Ops Manager organization member can exploit it against another member in the same organization or project. The attacker must have valid membership and the target must have a pending, unconfirmed authenticator enrollment.
What information is exposed and when?
The affected user-listing endpoints can disclose the target member's pending authenticator enrollment seed. Exposure is limited to the period before the target confirms the enrollment.
How can we determine whether we may be affected?
Review whether organization or project members can access user-listing endpoints and whether users have pending MFA authenticator enrollments. The referenced Ops Manager release notes identify version 8.0.27 as relevant.