Description
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Published: 2026-08-13
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper validation of SAML assertions in ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8551 allows an attacker to bypass authentication. The flaw permits the submission of forged SAML tokens that are accepted by the service provider without verifying the issuer or signature, enabling unauthorized access to the application and its protected resources. This weakness falls under CWE‑347, which involves invalid authentication leading to compromised credentials.

Affected Systems

ManageEngine PAM360 (Zohocorp) versions earlier than 8551 and ManageEngine Password Manager Pro (Zohocorp) versions earlier than 13232 are affected. These products expose organizations to risk when SAML configuration is not properly validated.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. While the EPSS score is not available and the vulnerability is not listed in CISA KEV, the likely attack vector is forging a SAML assertion or manipulating the response from an impersonated or compromised identity provider. Based on the description, it is inferred that the attacker can generate a valid assertion that bypasses authentication without requiring direct access to an existing identity provider. Once accepted, the attacker gains full authentication, enabling unrestricted access to protected resources and potential privilege escalation.

Generated by OpenCVE AI on August 13, 2026 at 11:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to ManageEngine PAM360 v8551 or newer.
  • Upgrade to ManageEngine Password Manager Pro v13232 or newer.
  • Ensure all SAML responses are signed and validated by the service provider during authentication.

Generated by OpenCVE AI on August 13, 2026 at 11:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Description Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Title Authentication Bypass
First Time appeared Zohocorp
Zohocorp manageengine Pam360
Zohocorp manageengine Password Manager Pro
Weaknesses CWE-347
CPEs cpe:2.3:a:zohocorp:manageengine_pam360:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_password_manager_pro:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Pam360
Zohocorp manageengine Password Manager Pro
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zohocorp Manageengine Pam360 Manageengine Password Manager Pro
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-08-13T10:18:35.174Z

Reserved: 2026-06-15T10:28:47.528Z

Link: CVE-2026-12263

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T11:17:38.193

Modified: 2026-08-13T11:17:38.193

Link: CVE-2026-12263

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T11:45:03Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature