CVE-2026-14913

8.8

ZohoCorp · ManageEngine OpManager and Firewall Analyzer

ZohoCorp ManageEngine OpManager and Firewall Analyzer are affected by an SQL injection vulnerability in the Rule Management Search Reports feature, allowing potential database compromise.

Executive summary

A high-severity SQL injection vulnerability in ManageEngine OpManager and Firewall Analyzer allows authenticated attackers to potentially compromise the integrity and confidentiality of the underlying database.

Vulnerability

The application is susceptible to an SQL injection attack via the Rule Management Search Reports functionality. Based on the CVSS vector (PR:L), this flaw requires an attacker to have low-level user privileges to trigger the malicious SQL commands.

Business impact

Successful exploitation of this vulnerability permits an attacker to execute arbitrary SQL commands against the database, leading to unauthorized data access, modification, or deletion. With a CVSS score of 8.8, this flaw represents a significant risk to organizational data integrity and confidentiality. Failure to remediate could result in the total compromise of the application backend and potential lateral movement within the network.

Remediation

Immediate Action: Update both ManageEngine OpManager and Firewall Analyzer to version 12.8.670 or later immediately to resolve the vulnerable code path.

Proactive Monitoring: Monitor database query logs for unusual patterns, such as unexpected syntax, unauthorized access attempts, or large-scale data extraction queries originating from the application service account.

Compensating Controls: Implement a Web Application Firewall (WAF) with strict SQL injection protection rules to inspect and block malicious input targeting the Rule Management Search Reports endpoint.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the critical nature of the affected products in network management, organizations must prioritize patching these systems. Administrators should verify their current version and apply the 12.8.670 update during the next available maintenance window to eliminate the risk of database exploitation.

More ZohoCorp CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources