Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution. | |
| Title | Remote Code Execution Vulnerability | |
| First Time appeared |
Zohocorp
Zohocorp manageengine Netflow Analyzer Zohocorp manageengine Network Configuration Manager Zohocorp manageengine Opmanager |
|
| Weaknesses | CWE-1336 | |
| CPEs | cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:*:*:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:*:*:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Zohocorp
Zohocorp manageengine Netflow Analyzer Zohocorp manageengine Network Configuration Manager Zohocorp manageengine Opmanager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zohocorp
Published:
Updated: 2026-09-23T12:59:12.952Z
Reserved: 2026-06-16T05:07:06.783Z
Link: CVE-2026-12370
Updated: 2026-09-23T12:59:00.973Z
Status : Received
Published: 2026-09-23T12:17:05.373
Modified: 2026-09-23T13:17:26.177
Link: CVE-2026-12370
No data.
OpenCVE Enrichment
Updated: 2026-09-23T16:30:07Z
-
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine