This document addresses "Remote Code Execution via NCM Configlet" reported in the monitoring component of RMM Central.
Severity: High
CVE ID: CVE-2026-12370
Affected version(s): Build 10.5.02 and below
Fixed version(s): Build 10.5.11
Fixed on: August 6, 2026
There was a Server-Side Template Injection (SSTI) vulnerability in Configlet processing that could potentially lead to remote code execution (RCE). This issue has now been fixed.
A Remote Code Execution (RCE) vulnerability on a server allows an unauthorized attacker to execute arbitrary commands or code with the privileges of the vulnerable application or server process.
This vulnerability was reported by C & N.
This vulnerability has been fixed on August 6, 2026 and the mitigation is available in build 10.5.11 with monitoring build 12.9.108.
Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the service pack page.
https://www.manageengine.com/remote-monitoring-management/service-packs.html
For any further questions or concerns, please reach out to us at rmmcentral-support@manageengine.com




