OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-84791

HIGH · CVSS 7.1 EPSS 0.60%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and earlier are susceptible to a Broken Access Control vulnerability, enabling authenticated low-privilege users to alter Change Management report schedule configurations for firewalls beyond their designated scope. This flaw poses a significant risk as it could lead to unauthorized changes in firewall management, potentially compromising network security. Organizations utilizing these affected versions should prioritize immediate remediation to mitigate the risk of unauthorized access and configuration changes.

CVE
CVE-2026-84791
Severity
HIGH
CVSS
7.1
EPSS
0.60%

Original NVD Description

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.