Unauthorized Path Traversal Vulnerability in Legacy Smart Update Manager - CVE-2026-15358

Severity: High

CVE ID: CVE-2026-15358

Product Name Affected Version(s) Fixed Version(s) Fixed On
OpManager Enterprise Edition
OpManager Nexus Enterprise Edition (formerly known as OpManager Plus Enterprise Edition)
Network Configuration Manager Enterprise Edition
OpManager MSP
12.8.670 and Below 12.8.671 and above 10-07-2026
12.8.676 to 12.8.737 12.8.738 and above 10-07-2026
12.9.000 to 12.9.116 12.9.117 and above (contact support) 09-07-2026

Note: Only the product editions and version ranges listed above are affected by CVE-2026-15358. All other editions remain unaffected, regardless of version.

Details:

Previously, an unauthorized path traversal vulnerability was identified in legacy Smart Update Manager on Probe installations. This issue has now been fixed.

Steps to upgrade:

  1. Kindly download the latest upgrade pack from the following links for the respective products:
  2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above links.

Source and Acknowledgements

This vulnerability was reported by qquynh.

Kindly contact our product support team for further details, at the below mentioned email address:

 

 
 Pricing  Get Quote