{"id":"CVE-2026-12370","published":"2026-09-23T12:17:05.373","lastModified":"2026-09-24T14:17:11.450","description":"ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.","cvssScore":7.6,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","cwes":["CWE-1336"],"vendors":[],"products":[],"references":[{"url":"https://www.manageengine.com/itom/advisory/cve-2026-12370.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}