Description
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
Published: 2026-09-23
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A permissions validation flaw in ZohoCorp ManageEngine Applications Manager allows a low‑privileged user to invoke administrator‑configured MBean actions on monitors outside the user’s assigned scope. This broken access control can be used to perform privileged operations such as modifying monitor settings, triggering tests, or collecting data that is normally restricted to administrators. The vulnerability is classified as CWE‑306.

Affected Systems

The affected product is Zohocorp ManageEngine Applications Manager, with vulnerable releases version 182200 and all earlier releases. No other vendors or products are listed as impacted.

Risk and Exploitability

The flaw has a CVSS score of 7.6 indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors include any environment in which a low‑privileged user can access the application and trigger MBean actions, such as internal networks or remote access to the management console. Because the flaw does not require elevated privileges to be exploited, the risk is that an attacker can elevate privileges or perform unauthorized administrative tasks within the application scope.

Generated by OpenCVE AI on September 23, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest stable release of ManageEngine Applications Manager that includes the fix for the permissions validation flaw.
  • Reconfigure the application to enforce strict role‑based access control, ensuring that only users with administrative privileges can trigger MBean actions and removing any default permissions granted to lower‑level roles.
  • Conduct a security review of user roles and monitor logs to verify that no unauthorized MBean activity remains and that the applied controls do not disrupt legitimate monitoring functions.

Generated by OpenCVE AI on September 23, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
Title Broken Access Control vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Applications Manager
Weaknesses CWE-306
CPEs cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Applications Manager
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Zohocorp Manageengine Applications Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-23T15:24:28.876Z

Reserved: 2026-09-08T09:53:28.947Z

Link: CVE-2026-86681

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T14:17:09.217

Modified: 2026-09-23T14:17:09.217

Link: CVE-2026-86681

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:30:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function