CVE-2026-2123
HIGH
8,6
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
A security audit identified a privilege escalation
vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions
Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of
Oneconsult AG for reporting this vulnerability
280
Improper Handling of Insufficient Permissions or Privileges
DraftCommon Consequences
Security Scopes Affected:
Other
Potential Impacts:
Other
Alter Execution Logic
Applicable Platforms
All platforms may be affected
https://portal.microfocus.com/s/article/KM000046068