Description
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.
Published: 2026-09-23
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

ZohoCorp ManageEngine Applications Manager versions 182000 and older suffered from a SQL injection flaw that could be exploited by a low-privileged user. The vulnerability allows the attacker to execute arbitrary SQL commands, which can lead to privilege escalation, granting full administrator rights and potentially remote code execution on the system. This constitutes a serious breach of confidentiality, integrity, and availability of the managed infrastructure.

Affected Systems

The affected product is Zohocorp ManageEngine Applications Manager, specifically releases 182000 and below. No other versions or related modules are listed as impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity and the lack of an EPSS score means current exploitation probability is unknown. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector involves a web interface or API that accepts unsanitized input, enabling an attacker with minimal privileges to craft malicious SQL payloads and thereby gain unrestricted access.

Generated by OpenCVE AI on September 23, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official vendor patch or upgrade to a release newer than version 182000.
  • Restrict low‑privileged user access to web interfaces that expose database queries and enforce strict role‑based permissions.
  • Implement database query logging and monitor for anomalous SQL activity to detect potential exploitation attempts.

Generated by OpenCVE AI on September 23, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.
Title Broken Authentication vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Applications Manager
Weaknesses CWE-89
CPEs cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Applications Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zohocorp Manageengine Applications Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-23T16:46:13.961Z

Reserved: 2026-09-08T09:47:26.701Z

Link: CVE-2026-86677

cve-icon Vulnrichment

Updated: 2026-09-23T16:37:01.064Z

cve-icon NVD

Status : Received

Published: 2026-09-23T14:17:08.803

Modified: 2026-09-23T17:17:18.093

Link: CVE-2026-86677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T16:45:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')