A security audit identified a privilege escalation
vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions
Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of
Oneconsult AG for reporting this vulnerability

Project Subscriptions

Vendors Products
Opentext Subscribe
Operations Agent Subscribe
Advisories

No advisories yet.

Fixes

Solution

The hotfix can be downloaded from the  Marketplace https://marketplace.opentext.com/itom/content/operations-agent-hotfix-for-cve-2026-2123-privilege-escalation/  for the OA versions mentioned below.  Please follow the readme.txt included in the hotfix zip file for install instructions.  OA 12.24 - HFWIN_1224028.tar, HFWIN_1224029.tar OA 12.25 - HFWIN_1225045.tar,HFWIN_1225046.tar  OA 12.26 - HFWIN_1226039.tar, HFWIN_1226040.tar OA 12.27 - HFWIN_1227023.tar, HFWIN_1227024.tar OA 12.28 - HFWIN_1228020.tar, HFWIN_1228021.tar OA 12.29 - HFWIN_1229006.tar, HFWIN_1229007.tar


Workaround

No workaround given by the vendor.

History

Wed, 01 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Opentext
Opentext operations Agent
Vendors & Products Opentext
Opentext operations Agent

Tue, 31 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 31 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
Description A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsult AG for reporting this vulnerability
Title Privilege escalation vulnerability in Operations Agent
Weaknesses CWE-280
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: OpenText

Published:

Updated: 2026-03-31T18:00:56.901Z

Reserved: 2026-02-06T14:55:51.920Z

Link: CVE-2026-2123

cve-icon Vulnrichment

Updated: 2026-03-31T18:00:14.961Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-31T18:16:46.293

Modified: 2026-04-01T14:24:02.583

Link: CVE-2026-2123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-31T20:37:45Z

Weaknesses