CVE-2026-11840
8.8Zohocorp · ManageEngine Password Manager Pro and PAM360
Zohocorp ManageEngine Password Manager Pro and PAM360 are vulnerable to an authenticated SQL injection flaw, which could allow an attacker to execute arbitrary SQL commands.
Executive summary
An authenticated SQL injection vulnerability in Zohocorp ManageEngine products allows attackers with low privileges to compromise database integrity and confidentiality.
Vulnerability
This is an SQL injection vulnerability (CWE-89) triggered by improper input sanitization. The vulnerability requires the attacker to have authenticated access (PR:L) to the system to exploit the flaw.
Business impact
Successful exploitation permits an attacker to manipulate database queries, potentially leading to unauthorized data exfiltration, modification of sensitive administrative credentials, or full system compromise. With a CVSS score of 8.8, this high-severity vulnerability poses a significant risk to the security of privileged access management environments, where the confidentiality and integrity of stored secrets are paramount.
Remediation
Immediate Action: Administrators must upgrade ManageEngine Password Manager Pro to version 13232 or higher, and PAM360 to version 8552 or higher immediately.
Proactive Monitoring: Review database access logs for anomalous query patterns, specifically those containing unexpected SQL syntax or unauthorized access attempts to sensitive tables.
Compensating Controls: Ensure that the database service account operates with the principle of least privilege, limiting its ability to execute administrative or system-level commands, and utilize a Web Application Firewall to filter malicious SQL payloads.
Exploitation status
Public Exploit Available: No confirmed public exploit available.
Analyst recommendation
Given the critical role of these products in managing organizational secrets, the risk of credential exposure is severe. Organizations should prioritize patching these systems within their next maintenance window to prevent potential unauthorized access to the underlying database.