Broken Access Control vulnerability- CVE-2026-84791

Severity: High

CVE ID: CVE-2026-84791

Product nameAffected Version(s)Fixed Version(s)Fixed On
OpManager
OpManager Enterprise Edition
OpManager Nexus
OpManager Nexus Enterprise Edition
Firewall Analyzer
12.8.710 and below12.8.711 and above*01-09-2026
12.8.718 to 12.9.12412.9.125 and above*03-09-2026
12.9.133 to 12.9.13412.9.135 and above28-08-2026

Note: This security vulnerability is applicable only for users of Firewall Analyzer, and for OpManager/Enterprise Edition/Nexus users with the Firewall Analyzer Plugin enabled.

Details:

A broken access control vulnerability allowed an authenticated low-privilege user to modify the Change Management report schedule configuration for firewalls outside their assigned scope. This issue has now been fixed.

Impact:

A low-privilege user could modify or reschedule Change Management report schedules associated with unassigned firewalls. This could affect the intended report-delivery configuration for those firewalls.

Fix:

The affected operations now validate the user's assigned firewall scope before allowing changes to a Change Management report schedule. Users can modify schedules only for firewalls within their authorized scope.

Steps to upgrade:

  1. Download the latest upgrade pack from here.
  2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above step.

Source and Acknowledgements

This vulnerability was reported by sealldev.

Kindly contact our product support teams for further details, at the email address mentioned below: