Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope. | |
| Title | Broken Access Control vulnerability | |
| First Time appeared |
Zohocorp
Zohocorp manageengine Firewall Analyzer Zohocorp manageengine Opmanager |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:*:*:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Zohocorp
Zohocorp manageengine Firewall Analyzer Zohocorp manageengine Opmanager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zohocorp
Published:
Updated: 2026-09-23T12:43:29.855Z
Reserved: 2026-09-02T10:16:27.673Z
Link: CVE-2026-84789
No data.
Status : Received
Published: 2026-09-23T12:17:07.983
Modified: 2026-09-23T12:17:07.983
Link: CVE-2026-84789
No data.
OpenCVE Enrichment
No data.
-
CWE-639
Authorization Bypass Through User-Controlled Key