CVE-2026-14828

8.8

Zohocorp · ManageEngine Password Manager Pro, PAM360, and Access Manager Plus

Zohocorp ManageEngine products are vulnerable to an authenticated SQL injection flaw, which may allow an attacker with low-level privileges to manipulate database queries.

Executive summary

An authenticated SQL injection vulnerability in Zohocorp ManageEngine products allows low-privileged attackers to execute unauthorized database commands, posing a significant risk to data integrity and confidentiality.

Vulnerability

The vulnerability is a SQL injection flaw (CWE-89) triggered by improper neutralization of special elements in SQL commands. The CVSS vector PR:L indicates that the attacker must have low-level privileges to successfully exploit the vulnerability.

Business impact

The ability to perform SQL injection against a privileged management tool like Password Manager Pro or PAM360 creates a severe risk of total compromise. An attacker could extract sensitive credentials, modify administrative configurations, or disrupt core business operations, leading to potential data breaches and regulatory non-compliance. With a CVSS score of 8.8, this vulnerability is categorized as high severity and requires immediate attention to prevent unauthorized lateral movement within the network.

Remediation

Immediate Action: Upgrade all instances of Password Manager Pro to 13235, PAM360 to 8561, and Access Manager Plus to 4405 immediately.

Proactive Monitoring: Review database access logs for anomalous query patterns, such as unexpected syntax or unauthorized access attempts from standard user accounts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets designed to detect and block common SQL injection patterns to provide a layer of protection until patching is complete.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the central role these products play in enterprise credential and access management, the risk posed by this SQL injection vulnerability is substantial. Administrators must prioritize the application of the vendor-provided security patches to all affected environments as soon as possible. Failure to remediate could allow an authenticated attacker to gain unauthorized control over the most sensitive assets managed by these systems.

More Zohocorp CVEs

Sources