CVE-2026-12370
Last modified
CVE-2026-12370 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution..
Description
ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | ManageEngine OpManager | < 12.8.668 |
| Zohocorp | ManageEngine NetFlow Analyzer | < 12.8.668 |
| Zohocorp | ManageEngine Network Configuration Manager | < 12.8.668 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-12370?
How severe is CVE-2026-12370?
How do I fix CVE-2026-12370?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12360The JetEngine plugin for WordPress is vulnerable to SQL inje…7.5
- CVE-2026-12363The LoRaWAN Fragmented Data Block Transport service (subsys/…4.2
- CVE-2026-12364The user-space system-call verifier z_vrfy_z_log_msg_static_…8.4
- CVE-2026-12365A use-after-free exists in the Zephyr second-generation work…5.8
- CVE-2026-12366Zephyr's dynamic kernel-object disposal path unref_check() i…8.8
- CVE-2026-1237Vulnerable cross-model authorization in juju. If a charm's c…2.1
- CVE-2026-12372A Server-Side Request Forgery (SSRF) vulnerability exists in…3.7
- CVE-2026-12374Improper certificate validation and a time-of-check time-of-…6.4
- CVE-2026-12375The uncanny-automator-pro WordPress plugin before 7.3.0.6 wa…9.8
- CVE-2026-12376The Academy LMS WordPress plugin through 3.8.2 does not rest…4.3
- CVE-2026-12378The Appointment Booking Calendar Plugin and Scheduling Plugi…8.1
- CVE-2026-12379An Open Redirect vulnerability (CWE-601) exists in the OAuth…6.8
Are you affected by CVE-2026-12370?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
