Server-Side Template Injection Vulnerability in ZohoCorp Products
CVE-2026-12370

7.6HIGH

What is CVE-2026-12370?

A vulnerability has been identified in ZohoCorp's ManageEngine products, specifically affecting OpManager, NetFlow Analyzer, and Network Configuration Manager. This security flaw allows for Server-Side Template Injection during Configlet processing, which could potentially be exploited to execute arbitrary code remotely. It is crucial for users of versions 12.8.667 and below to assess their security posture and apply the necessary mitigations.

Affected Version(s)

ManageEngine NetFlow Analyzer 0 < 12.8.668

ManageEngine Network Configuration Manager 0 < 12.8.668

ManageEngine OpManager 0 < 12.8.668

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.