CVE-2026-84787: CWE-250 Execution with unnecessary privileges in Zohocorp ManageEngine OpManager
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
AI Analysis
Technical Summary
CVE-2026-84787 is a privilege escalation vulnerability in ZohoCorp ManageEngine OpManager and Firewall Analyzer (versions <=12.8.710). The flaw allows an authenticated low-privilege user to escalate their privileges to Administrator by exploiting the Report Profile import functionality. This is categorized under CWE-250, indicating execution with unnecessary privileges. The CVSS v3.1 score is 8.1, reflecting high impact on confidentiality and integrity with no impact on availability.
Potential Impact
An attacker with valid low-level credentials can elevate their privileges to Administrator, gaining full control over the affected ManageEngine OpManager or Firewall Analyzer instance. This can lead to unauthorized access to sensitive data and administrative functions, severely compromising the security posture of the affected system.
Mitigation Recommendations
No explicit patch or remediation details are provided in the vendor advisory. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to trusted users only and monitor for suspicious activity related to Report Profile imports.
CVE-2026-84787: CWE-250 Execution with unnecessary privileges in Zohocorp ManageEngine OpManager
Description
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
CVSS v3.1
Score 8.1high
Affected software
Zohocorp
ManageEngine OpManager
Zohocorp
ManageEngine Firewall Analyzer
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-84787 is a privilege escalation vulnerability in ZohoCorp ManageEngine OpManager and Firewall Analyzer (versions <=12.8.710). The flaw allows an authenticated low-privilege user to escalate their privileges to Administrator by exploiting the Report Profile import functionality. This is categorized under CWE-250, indicating execution with unnecessary privileges. The CVSS v3.1 score is 8.1, reflecting high impact on confidentiality and integrity with no impact on availability.
Potential Impact
An attacker with valid low-level credentials can elevate their privileges to Administrator, gaining full control over the affected ManageEngine OpManager or Firewall Analyzer instance. This can lead to unauthorized access to sensitive data and administrative functions, severely compromising the security posture of the affected system.
Mitigation Recommendations
No explicit patch or remediation details are provided in the vendor advisory. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to trusted users only and monitor for suspicious activity related to Report Profile imports.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Zohocorp
- Date Reserved
- 2026-09-02T10:15:39.335Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab3c000f7a7c54106bb6df2
Added to database: 09/23/2026, 12:03:12 UTC
Last enriched: 09/23/2026, 12:17:45 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.