Remote Code Execution vulnerability- CVE-2026-19599

Severity: High

CVE ID: CVE-2026-19599

Product nameAffected Version(s)Fixed Version(s)Fixed On
OpManager MSP128166 to 12870912871014-08-2026
128718 to 12900112900213-08-2026
129100 to 12910812910914-08-2026
129117 to 129122129123 and 12913314-08-2026

Details:

A Remote Code Execution vulnerability, exploitable by a customer administrator user on the MSP Central installed server, was identified in the Notification Profile module. This issue has now been fixed.

Impact:

This vulnerability could allow an attacker with customer administrator access to exploit an API that runs commands on the installed server, due to broken access control. This could result in the execution of the given command on the server as part of the profile functionality, potentially leading to remote code execution.

Fix:

The issue was mitigated by enforcing strict access control, so that only administrators of the MSP Central Server application can use such sensitive APIs as part of product functionality.

Steps to upgrade:

  1. Download the latest upgrade pack from here.
  2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above step.

Source and Acknowledgements

This vulnerability was reported by sealldev.

Kindly contact our product support teams for further details, at the email address mentioned below: