Junglewise Threat Intelligence

CVE-2026-84791: Zoho ManageEngine OpManager and Firewall Analyzer access control bypass

CVE-2026-84791 · Severity: high · CVSS 7.1 · Published 2026-09-23

Technologies: Zoho ManageEngine OpManager Nexus, Zoho ManageEngine OpManager, Zoho ManageEngine OpManager Enterprise Edition, Zoho ManageEngine Firewall Analyzer, Zoho ManageEngine OpManager Nexus Enterprise Edition. Vendors: Zoho.

Executive brief

Zoho ManageEngine OpManager and Firewall Analyzer are network and firewall management tools used by IT teams. A broken access control vulnerability allowed low-privilege users to modify Change Management report schedules for firewalls they were not authorized to access, potentially disrupting report delivery and visibility into unassigned firewall changes.

Technical details

A broken access control flaw in the Change Management report scheduling module failed to validate whether an authenticated user's assigned firewall scope included the target firewall before allowing modifications. An attacker with low-privilege credentials could modify or reschedule Change Management report configurations for any firewall in the system, bypassing intended access boundaries.

Affected products

  • Zoho ManageEngine OpManager 12.8.710 and below
  • Zoho ManageEngine OpManager Enterprise Edition 12.8.710 and below
  • Zoho ManageEngine OpManager Nexus 12.8.710 and below
  • Zoho ManageEngine OpManager Nexus Enterprise Edition 12.8.710 and below
  • Zoho ManageEngine Firewall Analyzer 12.8.710 and below, 12.8.718 to 12.9.124, 12.9.133 to 12.9.134

Timeline

  • 2026-09-23: disclosed: Vulnerability disclosed publicly
  • 2026-08-28: patched: Firewall Analyzer versions 12.9.135 and above patched
  • 2026-09-03: patched: Firewall Analyzer versions 12.9.125 and above patched
  • 2026-09-01: patched: OpManager/Enterprise Edition/Nexus versions 12.8.711 and above patched

References

Related threats