# Broken Access Control vulnerability — CVE-2026-84791
**Severity:** High
**CVE ID:** CVE-2026-84791
| Product name | Affected Version(s) | Fixed Version(s) | Fixed On |
|---|---|---|---|
| OpManager
OpManager Enterprise Edition
OpManager Nexus
OpManager Nexus Enterprise Edition
Firewall Analyzer | 12.8.710 and below | [12.8.711 and above*](https://www.manageengine.com/network-monitoring/service-packs.html) | 01-09-2026 |
| OpManager
OpManager Enterprise Edition
OpManager Nexus
OpManager Nexus Enterprise Edition
Firewall Analyzer | 12.8.718 to 12.9.124 | [12.9.125 and above*](https://www.manageengine.com/network-monitoring/itom-servicepack.html?service-pack=opm) | 03-09-2026 |
| OpManager
OpManager Enterprise Edition
OpManager Nexus
OpManager Nexus Enterprise Edition
Firewall Analyzer | 12.9.133 to 12.9.134 | 12.9.135 and above | 28-08-2026 |
**Note:** This security vulnerability is applicable only for users of Firewall Analyzer, and for OpManager/Enterprise Edition/Nexus users with the Firewall Analyzer Plugin enabled.
## Details
A broken access control vulnerability allowed an authenticated low-privilege user to modify the Change Management report schedule configuration for firewalls outside their assigned scope. This issue has now been fixed.
## Impact
A low-privilege user could modify or reschedule Change Management report schedules associated with unassigned firewalls. This could affect the intended report-delivery configuration for those firewalls.
## Fix
The affected operations now validate the user's assigned firewall scope before allowing changes to a Change Management report schedule. Users can modify schedules only for firewalls within their authorized scope.
## Steps to upgrade
1. Download the latest upgrade pack from [here](https://www.manageengine.com/network-monitoring/service-packs.html).
2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above step.
## Source and Acknowledgements
This vulnerability was reported by **sealldev**.
Kindly contact our product support teams for further details, at the email address mentioned below:
- OpManager: [opmanager-support@manageengine.com](mailto:opmanager-support@manageengine.com)