SQL Injection vulnerability in Rule Management Search Reports- CVE-2026-14913

Severity: High

Product Name Affected Version(s) Fixed Version(s) Fixed On
OpManager
OpManager Enterprise Edition
OpManager Nexus
OpManager Nexus Enterprise Edition
Firewall Analyzer
12.8.669 and below 12.8.670 and above* 06-07-2026
12.8.676 to 12.8.708 12.8.709 and above 21-07-2026
12.8.718 to 12.8.736 12.8.737 and above* 06-07-2026
12.9.000 to 12.9.105 12.9.106 and above 03-07-2026

* Hyperlinks are subjected to update on releases and will only reference the latest fixed versions.

Note: Only the product editions and version ranges listed above are affected by CVE-2026-14913. All other editions remain unaffected, regardless of version.

Details:

Previously, an SQL injection vulnerability was identified in Rule Management Search Reports. This issue has now been fixed.

Steps to upgrade:

  1. Kindly download the latest upgrade pack from the following links for the respective products:
  2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above links.

Source and Acknowledgements

This vulnerability was reported by NGOC HIEU.

Kindly contact our product support team for further details, at the below mentioned email address:

 

 
 Pricing  Get Quote