Severity: High
CVE ID: CVE-2026-84789
| Product name | Affected Version(s) | Fixed Version(s) | Fixed On |
|---|---|---|---|
| OpManager OpManager Enterprise Edition OpManager Nexus OpManager Nexus Enterprise Edition Firewall Analyzer | 12.8.710 and below | 12.8.711 and above* | 01-09-2026 |
| 12.8.718 to 12.9.124 | 12.9.125 and above* | 03-09-2026 | |
| 12.9.133 to 12.9.134 | 12.9.135 and above | 28-08-2026 |
Note: This security vulnerability is applicable only for users of Firewall Analyzer, and for OpManager/Enterprise Edition/Nexus users with the Firewall Analyzer Plugin enabled.
Details:
A broken access control vulnerability allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope. This issue has now been fixed.
Impact:
An low-privilege user could create alert notifications for unassigned firewalls, which could result in unauthorized alert delivery.
Fix:
The alert-notification creation operation now validates the user's assigned firewall scope. Users can create alert notifications only for firewalls within their authorized scope.
Steps to upgrade:
Source and Acknowledgements
This vulnerability was reported by sealldev.
Kindly contact our product support teams for further details, at the email address mentioned below: