Description
ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.
Published: 2026-09-23
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unprivileged Deletion of Service Monitors
Action: Patch Now
AI Analysis

Impact

A permission validation defect in ZohoCorp ManageEngine Applications Manager allows an authenticated user with low privileges to remove service monitors that fall outside the user’s authorized scope. The removal of these monitors disables visibility into the health and status of services that the user should not be able to delete, potentially masking outages, degrading alerting, and eroding confidence in monitoring data. This flaw does not provide a method for escalating privileges, but it does permit the attacker to erase critical monitoring artifacts and disrupt operational awareness.

Affected Systems

ZohoCorp ManageEngine Applications Manager versions 182000 and earlier are affected. The vulnerability resides in the monitoring module where delete operations are not properly constrained to the user’s designated scope. Any installation of these versions that permits low‑privileged users a delete capability is susceptible.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability is categorized as moderate to high severity. EPSS data is not available, and the flaw is not listed in CISA’s KEV catalog. Based on the description, the attacker must be authenticated as a low‑privileged user, suggesting a remote or local authenticated attack vector. The impact on availability and operational visibility is significant, as deleted monitors can lead to undetected downtime or configuration drift.

Generated by OpenCVE AI on September 23, 2026 at 16:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest ManageEngine Applications Manager patch that extends the deletion scope validation from the vendor’s security update page.
  • Restrict delete permissions for low‑privileged users to only their own service monitors by implementing role‑based access controls and disabling delete rights where not required.
  • Monitor audit logs for delete operations and investigate any unexpected deletions to detect unauthorized activity.

Generated by OpenCVE AI on September 23, 2026 at 16:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.
Title Broken Access Control vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Applications Manager
Weaknesses CWE-20
CPEs cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Applications Manager
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Zohocorp Manageengine Applications Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-23T16:46:14.107Z

Reserved: 2026-09-08T09:52:48.925Z

Link: CVE-2026-86679

cve-icon Vulnrichment

Updated: 2026-09-23T16:37:07.072Z

cve-icon NVD

Status : Received

Published: 2026-09-23T14:17:09.090

Modified: 2026-09-23T17:17:18.203

Link: CVE-2026-86679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T16:15:06Z

Weaknesses
  • CWE-20

    Improper Input Validation