cve-2026-12370

HIGH CVSS 7.6 fkie_nvd
Description

ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 7.6 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L 2.8 4.7 0fc0942c-577d-436f-ae8e-945763c79b02
NVD metadata
NVD status
Awaiting Analysis
Source identifier
0fc0942c-577d-436f-ae8e-945763c79b02
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "affectedData": [
        {
          "defaultStatus": "unaffected",
          "product": "ManageEngine OpManager",
          "vendor": "Zohocorp",
          "versions": [
            {
              "lessThan": "12.8.668",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "ManageEngine NetFlow Analyzer",
          "vendor": "Zohocorp",
          "versions": [
            {
              "lessThan": "12.8.668",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "ManageEngine Network Configuration Manager",
          "vendor": "Zohocorp",
          "versions": [
            {
              "lessThan": "12.8.668",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02"
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution."
    }
  ],
  "id": "CVE-2026-12370",
  "lastModified": "2026-09-23T18:17:31.543",
  "metrics": {
    "cvssMetricV31": [
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "NETWORK",
          "availabilityImpact": "LOW",
          "baseScore": 7.6,
          "baseSeverity": "HIGH",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "LOW",
          "privilegesRequired": "LOW",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
          "version": "3.1"
        },
        "exploitabilityScore": 2.8,
        "impactScore": 4.7,
        "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
        "type": "Secondary"
      }
    ],
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-12370",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "role": "CISA Coordinator",
          "timestamp": "2026-09-23T12:58:57.200605Z",
          "version": "2.0.3"
        }
      }
    ]
  },
  "published": "2026-09-23T12:17:05.373",
  "references": [
    {
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "url": "https://www.manageengine.com/itom/advisory/cve-2026-12370.html"
    }
  ],
  "sourceIdentifier": "0fc0942c-577d-436f-ae8e-945763c79b02",
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-1336"
        }
      ],
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "type": "Secondary"
    }
  ]
}
View JSON API Download JSON