Command Injection vulnerability- CVE-2026-76978

Severity: High

CVE ID: CVE-2026-76978

Product nameAffected Version(s)Fixed Version(s)Fixed On
OpManager
OpManager Enterprise Edition
OpManager Nexus
OpManager Nexus Enterprise Edition
Firewall Analyzer
12.8.709 and below12.8.710 and above*14-08-2026

Note: This security vulnerability is applicable only for users of Firewall Analyzer, and for OpManager/Enterprise Edition/Nexus users with the Firewall Analyzer Plugin enabled.

Details:

A command injection vulnerability in the Diagnose Settings feature allowed a crafted request parameter to inject arbitrary CLI commands into the authenticated firewall. This issue has now been fixed.

Impact:

A low-privilege user could execute arbitrary commands on the monitored firewall using the product's stored credentials.

Fix:

The Diagnose Settings feature has been removed from the product, eliminating the vulnerable command-construction and execution path.

Steps to upgrade:

  1. Download the latest upgrade pack from here.
  2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above step.

Source and Acknowledgements

This vulnerability was reported by qquynh.

Kindly contact our product support teams for further details, at the email address mentioned below: