CVE-2026-2123 Details
Description
A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsult AG for reporting this vulnerability
A privilege escalation vulnerability has been identified in OpenText Operations Agent versions through 12.29 on Windows. Under certain conditions, the agent may execute files from specific writable directories. This vulnerability allows a low-privileged user to execute code with SYSTEM-level rights on the local machine, requiring local system access.
A hotfix is available for download from the OpenText Marketplace. Instructions for installation can be found in the readme.txt file included with the hotfix. The hotfix is available for Operations Agent versions 12.24 through 12.29.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://portal.microfocus.com/s/article/KM000046068 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-280 | Improper Handling of Insufficient Permissions or Privileges | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microfocus operations agent | >= 12.22, <= 12.29 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2026 | Initial Analysis | [email protected] |
| Mar 31, 2026 | New CVE Received | [email protected] |