{"id":"CVE-2026-75825","published":"2026-09-23T13:17:28.557","lastModified":"2026-09-24T04:17:55.500","description":"ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-306"],"vendors":[],"products":[],"references":[{"url":"https://www.manageengine.com/itom/advisory/cve-2026-75825.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows an attacker to bypass authentication in ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled, leading to unauthorized access and potential system compromise.","exploitability":"Exploitation is relatively straightforward given the preconditions of the Application Manager Plugin being enabled. An attacker would need to have network access to the affected system.","blast_radius":"If exploited, this vulnerability could result in unauthorized access to the entire system, leading to data theft, service disruption, or further exploitation of the system.","remediation":"Upgrade to ZohoCorp ManageEngine OpManager version 12.8.711 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","network","web","vulnerability"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:57:21.675Z"}}