CVE-2026-12370 HIGH

CVE-2026-12370: Remote Code Execution Vulnerability

Vendor Zohocorp
Product ManageEngine OpManager
Weakness CWE-1336
Published September 23, 2026
Last update September 24, 2026

CVSS base score

7.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

What the vulnerability does

01Description

ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.

Key dates

02Disclosure timeline

September 23, 2026 CVE published
September 24, 2026 Record updated

Related vulnerabilities

04Related CVE