Unauthorized Path Traversal Vulnerability in Legacy Smart Update Manager - CVE-2026-15358

Severity: High

CVE ID: CVE-2026-15358

Product Name Affected Version(s) Fixed Version(s) Fixed On
OpManager Enterprise Edition
OpManager Nexus Enterprise Edition (formerly known as OpManager Plus Enterprise Edition)
Network Configuration Manager Enterprise Edition
OpManager MSP
12.8.670 and below 12.8.671* 10-07-2026
12.8.676 to 12.8.708 12.8.709 and above 21-07-2026
12.8.718 to 12.8.737 12.8.738 and above* 10-07-2026
12.9.000, 12.9.100 to 12.9.106 12.9.107 and above 11-07-2026

* Hyperlinks are subjected to update on releases and will only reference the latest fixed versions.

Note: Only the product editions and version ranges listed above are affected by CVE-2026-15358. All other editions remain unaffected, regardless of version.

Details:

Previously, an unauthorized path traversal vulnerability was identified in legacy Smart Update Manager on Probe installations. This issue has now been fixed.

Steps to upgrade:

  1. Kindly download the latest upgrade pack from the following links for the respective products:
  2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above links.

Source and Acknowledgements

This vulnerability was reported by qquynh.

Kindly contact our product support team for further details, at the below mentioned email address:

 

 
 Pricing  Get Quote