Severity: High
CVE ID: CVE-2026-84787
| Product name | Affected Version(s) | Fixed Version(s) | Fixed On |
|---|---|---|---|
| OpManager OpManager Enterprise Edition OpManager Nexus OpManager Nexus Enterprise Edition Firewall Analyzer | 12.8.710 and below | 12.8.711 and above* | 01-09-2026 |
| 12.8.718 to 12.9.124 | 12.9.125 and above* | 03-09-2026 | |
| 12.9.133 to 12.9.134 | 12.9.135 and above | 28-08-2026 |
Note: This security vulnerability is applicable only for users of Firewall Analyzer, and for OpManager/Enterprise Edition/Nexus users with the Firewall Analyzer Plugin enabled.
Details:
A privilege escalation vulnerability allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import. This issue has now been fixed.
Impact:
A low-privilege user could import a Report Profile containing unauthorized privilege settings and obtain Administrator-level access. This could allow the user to perform actions beyond their intended permissions.
Fix:
The Report Profile import operation now validates and restricts imported privilege settings based on the importing user's authorized role. Operator users can no longer gain Administrator privileges through Report Profile import.
Steps to upgrade:
Source and Acknowledgements
This vulnerability was reported by zeocrynt.
Kindly contact our product support teams for further details, at the email address mentioned below: