This document addresses an unauthorized path traversal vulnerability reported in the monitoring component of RMM Central.
Severity: High
CVE ID: CVE-2026-15358
Affected version(s): Build 10.5.02 and below
Fixed version(s): Build 10.5.11
Fixed on: August 6, 2026
An unauthorized path traversal vulnerability was identified in legacy Smart Update Manager on Probe installations. This issue has now been fixed.
An unauthorized path traversal vulnerability on a server allows an attacker to access files or directories outside the intended application directory by manipulating file paths.
This vulnerability was reported by qquynh.
These vulnerabilities have been fixed on August 6, 2026 and the mitigation is available in the build 10.5.11 with monitoring build 12.9.108.
Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the service pack page.
https://www.manageengine.com/remote-monitoring-management/service-packs.html
For any further questions or concerns, please reach out to us at rmmcentral-support@manageengine.com




