---
id: CVE-2026-2123
title: |-
  A security audit identified a privilege escalation
  vulnerability in Operations Agent(<=OA 12.29) on Windows
summary: >-
  A security audit identified a privilege escalation

  vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific
  conditions

  Operations Agent may run executables from specific writeable locations.Thanks
  to Manuel Rickli & Phili…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-280
vendor: microfocus
product: operations_agent
affected:
  - 'operations_agent >= 12.22, <= 12.29'
published: '2026-03-31'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-2123'
references:
  - url: 'https://portal.microfocus.com/s/article/KM000046068'
    label: security@opentext.com
tags:
  - nvd
epss: 0.00101
epssPercentile: 0.00997
ingestedAt: '2026-07-24T20:38:03.000Z'
---

## Overview

A security audit identified a privilege escalation
vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions
Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of
Oneconsult AG for reporting this vulnerability

## Affected

- `operations_agent >= 12.22, <= 12.29`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
