Severity: High
CVE ID: CVE-2026-15358
| Product Name | Affected Version(s) | Fixed Version(s) | Fixed On |
|---|---|---|---|
| OpManager Enterprise Edition OpManager Nexus Enterprise Edition (formerly known as OpManager Plus Enterprise Edition) Network Configuration Manager Enterprise Edition OpManager MSP |
12.8.670 and below | 12.8.671* | 10-07-2026 |
| 12.8.676 to 12.8.708 | 12.8.709 and above | 21-07-2026 | |
| 12.8.718 to 12.8.737 | 12.8.738 and above* | 10-07-2026 | |
| 12.9.000, 12.9.100 to 12.9.106 | 12.9.107 and above | 11-07-2026 |
* Hyperlinks are subjected to update on releases and will only reference the latest fixed versions.
Note: Only the product editions and version ranges listed above are affected by CVE-2026-15358. All other editions remain unaffected, regardless of version.
Details:
Previously, an unauthorized path traversal vulnerability was identified in legacy Smart Update Manager on Probe installations. This issue has now been fixed.
Steps to upgrade:
Source and Acknowledgements
This vulnerability was reported by qquynh.
Kindly contact our product support team for further details, at the below mentioned email address: