ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution. | |
| Title | Remote Code Execution Vulnerability | |
| First Time appeared |
Zohocorp
Zohocorp manageengine Netflow Analyzer Zohocorp manageengine Network Configuration Manager Zohocorp manageengine Opmanager |
|
| Weaknesses | CWE-1336 | |
| CPEs | cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:*:*:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:*:*:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Zohocorp
Zohocorp manageengine Netflow Analyzer Zohocorp manageengine Network Configuration Manager Zohocorp manageengine Opmanager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zohocorp
Published:
Updated: 2026-09-23T11:20:09.186Z
Reserved: 2026-06-16T05:07:06.783Z
Link: CVE-2026-12370
No data.
Status : Received
Published: 2026-09-23T12:17:05.373
Modified: 2026-09-23T12:17:05.373
Link: CVE-2026-12370
No data.
OpenCVE Enrichment
No data.
Weaknesses