Executive brief
ManageEngine OpManager and Firewall Analyzer are network monitoring and firewall management tools used by enterprises to oversee their IT infrastructure. A broken access control vulnerability allowed low-privilege authenticated users to create alert notifications for firewalls outside their assigned scope, potentially enabling unauthorized alert delivery and scope violations. The vulnerability affects versions 12.8.710 and below across both products and has been patched.
Technical details
A broken access control vulnerability in OpManager and Firewall Analyzer failed to validate a low-privilege user's firewall scope when creating alert notifications, permitting access to unassigned resources. The flaw requires prior authentication but allows privilege escalation through scope bypass. The fix validates the user's assigned firewall scope before allowing alert-notification creation operations.
Affected products
- ZohoCorp ManageEngine OpManager 12.8.710 and below
- ZohoCorp ManageEngine OpManager Enterprise Edition 12.8.710 and below
- ZohoCorp ManageEngine OpManager Nexus 12.8.710 and below
- ZohoCorp ManageEngine OpManager Nexus Enterprise Edition 12.8.710 and below
- ZohoCorp ManageEngine Firewall Analyzer 12.8.710 and below; 12.8.718 to 12.9.124; 12.9.133 to 12.9.134
Timeline
- 2026-09-23: disclosed: Vulnerability published
- 2026-08-28: patched: Fixed in Firewall Analyzer 12.9.135 and above
- 2026-09-03: patched: Fixed in Firewall Analyzer 12.9.125 and above
- 2026-09-01: patched: Fixed in OpManager variants 12.8.711 and above