Executive brief
Zoho ManageEngine OpManager and Firewall Analyzer are network monitoring and management tools. Versions 12.8.669 and below contain an SQL injection vulnerability in the Rule Management Search Reports feature that could allow an attacker to execute arbitrary SQL queries and gain unauthorized access to sensitive data stored in the application database.
Technical details
An SQL injection vulnerability exists in the Rule Management Search Reports component of OpManager and Firewall Analyzer versions 12.8.669 and below. The vulnerability allows attackers to inject malicious SQL commands through user-supplied input, potentially leading to unauthorized database access and data exfiltration. Patches are available in OpManager 12.8.670+, Firewall Analyzer 12.8.709+, OpManager Nexus 12.8.737+, and versions 12.9.106+.
Affected products
- Zoho OpManager 12.8.669 and below
- Zoho OpManager Enterprise Edition 12.8.669 and below
- Zoho OpManager Nexus 12.8.718 to 12.8.736
- Zoho OpManager Nexus Enterprise Edition 12.8.718 to 12.8.736
- Zoho Firewall Analyzer 12.8.669 and below, 12.8.676 to 12.8.708, 12.9.000 to 12.9.105
Timeline
- 2026-09-23: disclosed
- 2026-07-06: patched: OpManager and OpManager Nexus Enterprise Edition patch released