CVE-2026-14913
8.8 HIGHPublished 2026-09-23 · Updated 2026-09-24
AI risk analysis
- Summary
- This vulnerability allows an attacker to inject malicious SQL queries, potentially leading to data theft, manipulation, or system compromise.
- Exploitability
- Exploitation requires access to the affected version of ZohoCorp ManageEngine OpManager or Firewall Analyzer, and knowledge of the SQL injection point.
- Blast radius
- If exploited, the attacker could gain full control over the system, leading to severe data breaches or system compromise.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to ZohoCorp ManageEngine OpManager and Firewall Analyzer version 12.8.670 or later.
sql-injectiondata-theftsystem-compromise
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-86595
- HIGHCVE-2022-4997
- CRITICALCVE-2023-54399
- CRITICALCVE-2023-54400PoC
- CRITICALCVE-2025-63564
- MEDIUMCVE-2026-11421
- CRITICALCVE-2026-12718
- MEDIUMCVE-2026-14872
Related by shared AI tags and CWE weakness class. Browse the full archive.