{"affected":[],"aliases":["CVE-2026-84791"],"database_specific":{"cwe_ids":["CWE-639"],"github_reviewed":false,"github_reviewed_at":null,"nvd_published_at":"2026-09-23T12:17:08Z","severity":"HIGH"},"details":"ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.","id":"GHSA-hm59-9xmm-qvw8","modified":"2026-09-23T12:31:15Z","published":"2026-09-23T12:31:15Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84791"},{"type":"WEB","url":"https://www.manageengine.com/itom/advisory/cve-2026-84791.html"}],"schema_version":"1.4.0","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","type":"CVSS_V3"}]}