Unauthorized Path Traversal Vulnerability in ZohoCorp ManageEngine OpManager and Network Configuration Manager
CVE-2026-15358
7.5HIGH
What is CVE-2026-15358?
ZohoCorp's ManageEngine OpManager and Network Configuration Manager prior to version 12.8.671 are susceptible to an unauthorized Path Traversal vulnerability, which may allow attackers to read sensitive files on the server. This issue arises due to improper validation of user-supplied input, potentially leading to unauthorized access to critical system files.
Affected Version(s)
ManageEngine Network Configuration Manager 0 < 12.8.671
ManageEngine OpManager 0 < 12.8.671