# XML Injection Vulnerability — CVE-2026-76979 **Severity:** High **CVE ID:** CVE-2026-76979 | Product name | Affected Version(s) | Fixed Version(s) | Fixed On | |---|---|---|---| | OpManager
OpManager Enterprise Edition
OpManager Nexus
OpManager Nexus Enterprise Edition
Firewall Analyzer | 12.8.709 and below | 12.8.710 and above* | 14-08-2026 | | OpManager
OpManager Enterprise Edition
OpManager Nexus
OpManager Nexus Enterprise Edition
Firewall Analyzer | 12.8.718 to 12.9.122 | 12.9.124 and above* | 20-08-2026 | **Note:** This security vulnerability is applicable only for users of Firewall Analyzer, and for OpManager/Enterprise Edition/Nexus users with the Firewall Analyzer Plugin enabled. ## Details The Compare Policies feature in Rule Tracking, which lets users upload two firewall-configuration files for comparison, was found to be vulnerable to XML injection due to insufficient validation of the uploaded files. This issue has now been fixed. ## Impact A low-privilege user could upload a crafted configuration file to read arbitrary files on the server, trigger unauthorized outbound requests, or cause a denial of service. ## Fix Uploaded configuration files are now securely validated before comparison, preventing XML injection. ## Steps to Upgrade 1. Download the latest upgrade pack from [here](https://www.manageengine.com/network-monitoring/service-packs.html). 2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above step. ## Source and Acknowledgements This vulnerability was reported by **qquynh**. ## Support Kindly contact our product support teams for further details, at the email address mentioned below: - OpManager: [opmanager-support@manageengine.com](mailto:opmanager-support@manageengine.com)