Executive brief
Zoho ManageEngine OpManager and Firewall Analyzer are network management tools used by organizations to monitor infrastructure and security devices. A vulnerability allows authenticated low-privilege users to escalate their access to administrator level by importing specially crafted Report Profiles, potentially enabling unauthorized system changes and full administrative control.
Technical details
The vulnerability is a privilege escalation in the Report Profile import functionality affecting OpManager and Firewall Analyzer versions 12.8.710 and below. An authenticated user with low privileges can import a malicious Report Profile containing unauthorized privilege settings to gain administrator access. The fix validates and restricts imported privilege settings based on the importing user's authorized role.
Affected products
- Zoho ManageEngine OpManager 12.8.710 and below
- Zoho ManageEngine OpManager Enterprise Edition 12.8.710 and below
- Zoho ManageEngine OpManager Nexus 12.8.710 and below
- Zoho ManageEngine OpManager Nexus Enterprise Edition 12.8.710 and below
- Zoho ManageEngine Firewall Analyzer 12.8.710 and below
Timeline
- 2026-09-23: disclosed
- 2026-09-01: patched: OpManager version 12.8.711 and above released
- 2026-09-03: patched: Firewall Analyzer version 12.9.125 and above released