CVE-2026-19599
9.9Zohocorp · ManageEngine OpManager
ManageEngine OpManager contains an OS command injection vulnerability in the Notification Profile module, allowing remote code execution by an authenticated user.
Executive summary
A critical OS command injection vulnerability in Zohocorp ManageEngine OpManager allows an authenticated attacker to achieve remote code execution on the underlying system.
Vulnerability
The application is susceptible to OS command injection (CWE-78) within the Notification Profile module. This flaw permits an authenticated user with low privileges to execute arbitrary system commands with the permissions of the service account.
Business impact
Successful exploitation of this vulnerability grants an attacker full control over the ManageEngine OpManager server. Given the 9.9 CVSS score, this represents a severe threat to confidentiality, integrity, and availability, as it could lead to total system compromise, exfiltration of sensitive monitoring data, and lateral movement throughout the corporate network.
Remediation
Immediate Action: Update Zohocorp ManageEngine OpManager to version 12.8.711 or later as specified in the official vendor advisory.
Proactive Monitoring: Review application logs and system audit trails for unusual shell invocations or unexpected processes originating from the OpManager service account.
Compensating Controls: Implement strict network segmentation and egress filtering to prevent the server from initiating unauthorized external connections while the patch is being deployed.
Exploitation status
Public Exploit Available: No — exploit_available (unknown).
Analyst recommendation
Due to the critical nature of this remote code execution flaw, organizations should prioritize the immediate application of the vendor-supplied update. Ensure that access to the OpManager administrative interface is restricted to authorized personnel only to minimize the risk of exploitation by low-privileged users.
More Zohocorp CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section