CVE-2026-2123: Micro Focus Operations Agent

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsult AG for reporting this vulnerability

Affected products

  • Micro Focus Operations Agent: from 12.22, up to and including 12.29

Published 2026-03-31. Last modified 2026-07-24.