{"id":"CVE-2026-14913","published":"2026-09-23T12:17:05.507","lastModified":"2026-09-24T04:17:39.397","description":"ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://www.manageengine.com/itom/advisory/cve-2026-14913.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows an attacker to inject malicious SQL queries, potentially leading to data theft, manipulation, or system compromise.","exploitability":"Exploitation requires access to the affected version of ZohoCorp ManageEngine OpManager or Firewall Analyzer, and knowledge of the SQL injection point.","blast_radius":"If exploited, the attacker could gain full control over the system, leading to severe data breaches or system compromise.","remediation":"Upgrade to ZohoCorp ManageEngine OpManager and Firewall Analyzer version 12.8.670 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["sql-injection","data-theft","system-compromise"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:57:15.369Z"}}