Severity: High
CVE ID: CVE-2026-19599
| Product name | Affected Version(s) | Fixed Version(s) | Fixed On |
|---|---|---|---|
| OpManager MSP | 128166 to 128709 | 128710 | 14-08-2026 |
| 128718 to 129001 | 129002 | 13-08-2026 | |
| 129100 to 129108 | 129109 | 14-08-2026 | |
| 129117 to 129122 | 129123 and 129133 | 14-08-2026 |
Details:
A Remote Code Execution vulnerability, exploitable by a customer administrator user on the MSP Central installed server, was identified in the Notification Profile module. This issue has now been fixed.
Impact:
This vulnerability could allow an attacker with customer administrator access to exploit an API that runs commands on the installed server, due to broken access control. This could result in the execution of the given command on the server as part of the profile functionality, potentially leading to remote code execution.
Fix:
The issue was mitigated by enforcing strict access control, so that only administrators of the MSP Central Server application can use such sensitive APIs as part of product functionality.
Steps to upgrade:
Source and Acknowledgements
This vulnerability was reported by sealldev.
Kindly contact our product support teams for further details, at the email address mentioned below: