CVE-2026-12263

8.8

Zohocorp · ManageEngine Password Manager Pro / PAM360

ManageEngine Password Manager Pro and PAM360 are vulnerable to authentication bypass due to improper SAML signature verification, allowing unauthorized access to the application.

Executive summary

An authentication bypass vulnerability in Zohocorp ManageEngine products allows attackers to circumvent security controls due to flawed SAML signature validation.

Vulnerability

The vulnerability stems from improper verification of cryptographic signatures (CWE-347) within the SAML implementation. An attacker can craft malicious SAML assertions to bypass authentication mechanisms and gain unauthorized access to the application.

Business impact

The CVSS score of 8.8 underscores the gravity of this authentication bypass in products designed for privileged access management. Unauthorized access to these platforms could grant an attacker control over highly sensitive credentials, leading to widespread compromise of the entire enterprise infrastructure.

Remediation

Immediate Action: Update ManageEngine Password Manager Pro to version 13232 or higher, and PAM360 to version 8551 or higher, immediately.

Proactive Monitoring: Audit authentication logs for suspicious login activity or unauthorized access attempts occurring via SAML identity providers.

Compensating Controls: If immediate patching is not feasible, restrict network access to the management interfaces of these applications to known trusted IP addresses.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given that these tools manage the most sensitive credentials in an organization, this update is critical. Administrators must apply the patches immediately and verify the integrity of their SAML configurations to prevent unauthorized access.

More Zohocorp CVEs