Privilege Escalation vulnerability- CVE-2026-84787

Severity: High

CVE ID: CVE-2026-84787

Product nameAffected Version(s)Fixed Version(s)Fixed On
OpManager
OpManager Enterprise Edition
OpManager Nexus
OpManager Nexus Enterprise Edition
Firewall Analyzer
12.8.710 and below12.8.711 and above*01-09-2026
12.8.718 to 12.9.12412.9.125 and above*03-09-2026
12.9.133 to 12.9.13412.9.135 and above28-08-2026

Note: This security vulnerability is applicable only for users of Firewall Analyzer, and for OpManager/Enterprise Edition/Nexus users with the Firewall Analyzer Plugin enabled.

Details:

A privilege escalation vulnerability allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import. This issue has now been fixed.

Impact:

A low-privilege user could import a Report Profile containing unauthorized privilege settings and obtain Administrator-level access. This could allow the user to perform actions beyond their intended permissions.

Fix:

The Report Profile import operation now validates and restricts imported privilege settings based on the importing user's authorized role. Operator users can no longer gain Administrator privileges through Report Profile import.

Steps to upgrade:

  1. Download the latest upgrade pack from here.
  2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above step.

Source and Acknowledgements

This vulnerability was reported by zeocrynt.

Kindly contact our product support teams for further details, at the email address mentioned below: