CVE-2026-12370

Summary

ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.

Affected Software

VendorProductVersion RangeStatus
ZohocorpManageEngine OpManager0 < 12.8.668affected
ZohocorpManageEngine NetFlow Analyzer0 < 12.8.668affected
ZohocorpManageEngine Network Configuration Manager0 < 12.8.668affected

Weaknesses

  • CWE-1336: CWE-1336 Improper neutralization of special elements used in a template engine

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References