XML Injection Vulnerability in ZohoCorp ManageEngine OpManager and Firewall Analyzer
CVE-2026-76979

7.7HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
23 September 2026

What is CVE-2026-76979?

An XML Injection vulnerability exists in the Rule Tracking Compare Policies feature of ZohoCorp's ManageEngine OpManager and Firewall Analyzer. This flaw enables malicious actors to manipulate XML input, potentially leading to unauthorized access and data exposure. It is crucial for users of versions 12.8.709 and earlier to apply security measures promptly to mitigate the risks associated with this vulnerability.

Affected Version(s)

ManageEngine Firewall Analyzer 0 < 12.8.710

ManageEngine OpManager 0 < 12.8.710

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.