Unauthorized Path Traversal Vulnerability in Legacy Smart Update Manager - CVE-2026-15358

This document addresses an unauthorized path traversal vulnerability reported in the monitoring component of RMM Central.

Severity: High

CVE ID: CVE-2026-15358

Affected version(s): Build 10.5.02 and below

Fixed version(s): Build 10.5.11

Fixed on: August 6, 2026

What was the problem?

An unauthorized path traversal vulnerability was identified in legacy Smart Update Manager on Probe installations. This issue has now been fixed.

Impact of the Vulnerability

An unauthorized path traversal vulnerability on a server allows an attacker to access files or directories outside the intended application directory by manipulating file paths.

Credits and acknowledgments

This vulnerability was reported by qquynh.

How do I fix it?

These vulnerabilities have been fixed on August 6, 2026 and the mitigation is available in the build 10.5.11 with monitoring build 12.9.108.

Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the service pack page.

https://www.manageengine.com/remote-monitoring-management/service-packs.html

 

Help

For any further questions or concerns, please reach out to us at rmmcentral-support@manageengine.com

Trusted by leading brands across industry verticals