Executive brief
ManageEngine OpManager and Network Configuration Manager are network monitoring and management tools used by IT operations teams to oversee infrastructure. A path traversal vulnerability in the legacy Smart Update Manager on probe installations could allow unauthorized access to files outside intended directories, potentially exposing sensitive configuration data or enabling system compromise. The issue affects multiple product editions with versions before 12.8.671 and has been patched.
Technical details
An unauthorized path traversal vulnerability exists in the legacy Smart Update Manager component on Probe installations in OpManager and Network Configuration Manager. The vulnerability allows attackers to access files outside restricted directories without authentication, potentially leading to information disclosure or further system compromise. Patches are available with fixed versions 12.8.671 (OpManager Enterprise/NCM Enterprise), 12.8.709 (OpManager Nexus), 12.8.738 (OpManager MSP), and 12.9.107 (later releases).
Affected products
- Zoho ManageEngine OpManager Enterprise Edition 12.8.670 and below
- Zoho ManageEngine OpManager Nexus Enterprise Edition 12.8.676 to 12.8.708
- Zoho ManageEngine Network Configuration Manager Enterprise Edition 12.8.718 to 12.8.737
- Zoho ManageEngine OpManager MSP 12.9.000, 12.9.100 to 12.9.106
Timeline
- 2026-09-23: disclosed
- 2026-07-10: patched: OpManager Enterprise and NCM Enterprise patched (12.8.671)
- 2026-07-21: patched: OpManager Nexus patched (12.8.709)
- 2026-07-10: patched: OpManager MSP patched (12.8.738)
- 2026-07-11: patched: Later releases patched (12.9.107)