Description
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
Published: 2026-09-23
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Unauthorized access to Google Cloud resources via exposed service‑account key
Action: Immediate patch
AI Analysis

Impact

The vulnerability is a credential compromise in ZohoCorp’s ManageEngine Applications Manager installer, which contains a Google Cloud service‑account private key. An unauthenticated attacker who obtains the installer can extract the key and use it to impersonate the service account, thereby gaining full read/write/management privileges over the associated Cloud resources. This flaw maps to CWE‑321, a known issue of improper key management leading to data exposure and unauthorized access.

Affected Systems

The issue affects Zohocorp’s ManageEngine Applications Manager versions 182200 and earlier. Administrators should review whether any systems are running these specific versions or older releases and consider updating to the latest certified build.

Risk and Exploitability

The CVSS score of 10 classifies this as a critical vulnerability, although the EPSS score is not available, indicating that exploitation probability data is missing. The KEV catalog does not list this flaw, so there are no publicly confirmed exotic exploit packages, but the high severity and lack of a key restriction make it an attractive target. The likely attack vector is unauthenticated download or analysis of the installer, after which the attacker can extract the private key and impersonate the service account.

Generated by OpenCVE AI on September 23, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ManageEngine Applications Manager to a version newer than 182200 following the vendor’s official update instructions.
  • Avoid installing or distributing installers older than the patched build; if the installer must be used, obtain it directly from Zohocorp’s secured source and verify that the service‑account key is not present.
  • Enable and closely monitor Google Cloud IAM audit logs to detect any unauthorized use of the compromised service account.

Generated by OpenCVE AI on September 23, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
Title Sensitive data exposure
First Time appeared Zohocorp
Zohocorp manageengine Applications Manager
Weaknesses CWE-321
CPEs cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Applications Manager
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Zohocorp Manageengine Applications Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-23T13:11:31.276Z

Reserved: 2026-09-08T10:56:01.608Z

Link: CVE-2026-86708

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T14:17:09.467

Modified: 2026-09-23T14:17:09.467

Link: CVE-2026-86708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:30:07Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key