Authentication Bypass vulnerability- CVE-2026-75825

Severity: High

CVE ID: CVE-2026-75825

Product nameAffected Version(s)Fixed Version(s)Fixed On
Application Manager Plugin with:
OpManager
OpManager Enterprise Edition
OpManager Nexus
OpManager Nexus Enterprise Edition
12.8.510 to 12.9.13312.9.13420-08-2026
12.8.510 to 12.9.12312.9.12421-08-2026
12.8.510 to 12.8.71012.8.71101-09-2026

Note: This security vulnerability is applicable only for the above products with APM Plugin and APM Module enabled.

Details:

Previously, an authentication bypass vulnerability in the OpManager—APM Plugin login flow, affecting users with the APM module enabled, could allow privilege escalation under certain conditions. This issue has now been fixed.

Impact:

Under certain conditions, a logged-in OpManager user with access to the Applications Manager module could gain access to the Applications Manager Plugin as another account, including an administrator account, without knowing that account's password. This could give them higher privileges than they were granted.

Fix:

The SSO login has been strengthened so that a user can only be logged in as their own account. The login request is now verified against the identity of the user who initiated it, and any request that does not match is rejected.

Steps to upgrade:

  1. Download the latest upgrade pack from here.
  2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above step.

Source and Acknowledgements

This vulnerability was reported by sealldev.

Kindly contact our product support teams for further details, at the email address mentioned below: