Executive brief
Zoho ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager are network monitoring and management tools used by enterprises to oversee IT infrastructure. A server-side template injection flaw in Configlet processing allows unauthenticated attackers to achieve remote code execution on vulnerable systems, potentially compromising the entire managed network.
Technical details
A server-side template injection (SSTI) vulnerability exists in the Configlet processing component of OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below. The vulnerability allows remote code execution via template injection without requiring authentication. Patches are available in versions 12.8.668 and later.
Affected products
- Zoho ManageEngine OpManager 12.8.667 and below
- Zoho ManageEngine NetFlow Analyzer 12.8.667 and below
- Zoho ManageEngine Network Configuration Manager 12.8.667 and below
Timeline
- 2026-09-23: disclosed: CVE-2026-12370 published
- 2026-06-13: patched: OpManager fix released (12.8.668)
- 2026-06-19: patched: NetFlow Analyzer and Network Configuration Manager fixes released