CVE-2026-3324
8.2Zohocorp · ManageEngine Log360
ManageEngine Log360 versions 13000 through 13013 contain an authentication bypass vulnerability due to an improper filter configuration on specific actions.
Executive summary
An authentication bypass vulnerability in Zohocorp ManageEngine Log360 allows unauthenticated attackers to perform unauthorized actions, posing a significant risk to centralized log management security.
Vulnerability
The software suffers from an authentication bypass (CWE-288) caused by improper filter configuration. This flaw permits an unauthenticated attacker to interact with specific application actions without valid credentials.
Business impact
The vulnerability carries a CVSS score of 8.2, classifying it as High severity. Successful exploitation allows unauthorized parties to influence sensitive log management operations, potentially leading to the modification of security data, audit log manipulation, or unauthorized access to system configuration. Such compromise undermines the integrity of the entire security monitoring infrastructure.
Remediation
Immediate Action: Review the official ManageEngine security advisory and apply the provided security updates as soon as they become available. If a patch is not yet released, restrict network access to the Log360 interface to trusted management subnets only.
Proactive Monitoring: Monitor application access logs for unusual patterns, such as multiple requests to sensitive endpoints originating from unauthorized or unexpected IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule to intercept and block traffic attempting to access administrative endpoints without proper authentication headers or tokens.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the nature of the vulnerability allowing unauthenticated access, this issue should be treated as a priority. Administrators must prioritize applying vendor-supplied patches to all affected instances of ManageEngine Log360 to prevent potential unauthorized system manipulation.