OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-84789

HIGH · CVSS 7.1 EPSS 0.60%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and earlier are susceptible to a Broken Access Control vulnerability, enabling authenticated low-privilege users to generate alert notifications for firewalls beyond their designated scope. This could lead to unauthorized access and potential manipulation of firewall configurations, posing significant security risks. Organizations using these affected products should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-84789
Severity
HIGH
CVSS
7.1
EPSS
0.60%

Original NVD Description

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope.