Remote Code Execution vulnerability- CVE-2026-19599

Severity: High

CVE ID: CVE-2026-19599

Product nameAffected Version(s)Fixed Version(s)Fixed On
OpManager MSP12.8.166 to 12.8.70912.8.710 and above*14-08-2026
12.8.718 to 12.9.00112.9.002 and above*13-08-2026
12.9.100 to 12.9.10812.9.109 and above*14-08-2026
12.9.117 to 12.9.12212.9.123 and above*14-08-2026

* Hyperlinks are subject to update on releases and will only reference the latest fixed versions.

Details:

A Remote Code Execution vulnerability, exploitable by a customer administrator user on the MSP Central installed server, was identified in the Notification Profile module. This issue has now been fixed.

Impact:

This vulnerability could allow an attacker with customer administrator access to exploit an API that runs commands on the installed server, due to broken access control. This could result in the execution of the given command on the server as part of the profile functionality, potentially leading to remote code execution.

Fix:

The issue was mitigated by enforcing strict access control, so that only administrators of the MSP Central Server application can use such sensitive APIs as part of product functionality.

Steps to upgrade:

  1. Download the latest upgrade pack from here.
  2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above step.

Source and Acknowledgements

This vulnerability was reported by sealldev.

Kindly contact our product support teams for further details, at the email address mentioned below: