CVE-2026-12263
8.8Zohocorp · ManageEngine Password Manager Pro / PAM360
ManageEngine Password Manager Pro and PAM360 are vulnerable to authentication bypass due to improper SAML signature verification, allowing unauthorized access to the application.
Executive summary
An authentication bypass vulnerability in Zohocorp ManageEngine products allows attackers to circumvent security controls due to flawed SAML signature validation.
Vulnerability
The vulnerability stems from improper verification of cryptographic signatures (CWE-347) within the SAML implementation. An attacker can craft malicious SAML assertions to bypass authentication mechanisms and gain unauthorized access to the application.
Business impact
The CVSS score of 8.8 underscores the gravity of this authentication bypass in products designed for privileged access management. Unauthorized access to these platforms could grant an attacker control over highly sensitive credentials, leading to widespread compromise of the entire enterprise infrastructure.
Remediation
Immediate Action: Update ManageEngine Password Manager Pro to version 13232 or higher, and PAM360 to version 8551 or higher, immediately.
Proactive Monitoring: Audit authentication logs for suspicious login activity or unauthorized access attempts occurring via SAML identity providers.
Compensating Controls: If immediate patching is not feasible, restrict network access to the management interfaces of these applications to known trusted IP addresses.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given that these tools manage the most sensitive credentials in an organization, this update is critical. Administrators must apply the patches immediately and verify the integrity of their SAML configurations to prevent unauthorized access.