CVE-2026-87110: Ops Manager Uncontrolled Resource Consumption in Monitoring Endpoints
An unauthenticated user with network access to the Ops Manager web port can repeatedly request monitoring endpoints that perform costly work without rate limiting. This can temporarily slow other traffic served by the same process while requests continue.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated user who has network access to the Ops Manager web port can repeatedly request the affected monitoring endpoints. No credentials or user interaction are required.
What is the operational impact?
Repeated requests can consume resources and temporarily slow other traffic handled by the same process while the requests continue. The provided information indicates an availability impact, with no stated confidentiality or integrity impact.
Which deployments should be prioritized?
Prioritize Ops Manager instances whose web port is reachable by untrusted networks, because exploitation requires only network access to that port. Restricting access to the web port can reduce exposure when patching is not immediately possible.