CVE-2019-15106: Zohocorp ManageEngine Opmanager
Critical severity, CVSS 9.8. EPSS: 25.5% chance of exploitation in the next 30 days.
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm.
Affected products
- Zohocorp ManageEngine Opmanager: up to and including 12.4.034
Published 2019-08-16. Last modified 2026-06-17.