Severity: High
CVE ID: CVE-2026-76979
| Product name | Affected Version(s) | Fixed Version(s) | Fixed On |
|---|---|---|---|
| OpManager OpManager Enterprise Edition OpManager Nexus OpManager Nexus Enterprise Edition Firewall Analyzer | 12.8.718 to 12.9.122 | 12.9.124 and above* | 20-08-2026 |
Note: This security vulnerability is applicable only for users of Firewall Analyzer, and for OpManager/Enterprise Edition/Nexus users with the Firewall Analyzer Plugin enabled.
Details:
The Compare Policies feature in Rule Tracking, which lets users upload two firewall-configuration files for comparison, was found to be vulnerable to XML injection due to insufficient validation of the uploaded files. This issue has now been fixed.
Impact:
A low-privilege user could upload a crafted configuration file to read arbitrary files on the server, trigger unauthorized outbound requests, or cause a denial of service.
Fix:
Uploaded configuration files are now securely validated before comparison, preventing XML injection.
Steps to upgrade:
Source and Acknowledgements
This vulnerability was reported by qquynh.
Kindly contact our product support teams for further details, at the email address mentioned below: