cbcvebase.
CVE-2026-84791
published 2026-09-23

CVE-2026-84791: ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an…

PriorityP344high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.60%
46.3th percentile
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.

Affected

2 ranges
VendorProductVersion rangeFixed in
zohocorpmanageengine_firewall_analyzer< 12.8.71112.8.711
zohocorpmanageengine_opmanager< 12.8.71112.8.711
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.