{"affected":[],"aliases":["CVE-2026-12370"],"database_specific":{"cwe_ids":["CWE-1336"],"github_reviewed":false,"github_reviewed_at":null,"nvd_published_at":"2026-09-23T12:17:05Z","severity":"HIGH"},"details":"ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.","id":"GHSA-rxm6-4vc4-h8j2","modified":"2026-09-23T12:31:15Z","published":"2026-09-23T12:31:15Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12370"},{"type":"WEB","url":"https://www.manageengine.com/itom/advisory/cve-2026-12370.html"}],"schema_version":"1.4.0","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","type":"CVSS_V3"}]}