CVE-2026-5785

8.1

Zohocorp · ManageEngine PAM360 and Password Manager Pro

Zohocorp ManageEngine PAM360 and Password Manager Pro contain an authenticated SQL injection vulnerability within the query report module.

Executive summary

An authenticated SQL injection vulnerability in Zohocorp ManageEngine PAM360 and Password Manager Pro allows an attacker to compromise sensitive database information.

Vulnerability

The application is susceptible to SQL injection (CWE-89) within the query report module, which allows an authenticated user to execute arbitrary SQL commands against the backend database.

Business impact

Successful exploitation of this vulnerability allows an authenticated attacker to read or modify sensitive data stored within the ManageEngine database. Given the nature of these products as privileged access management tools, the compromise of stored credentials and configuration data poses a critical risk to the entire organizational infrastructure. The CVSS score of 8.1 reflects the high potential for impact on confidentiality and integrity.

Remediation

Immediate Action: Upgrade ManageEngine PAM360 to version 8531 or later, and update Password Manager Pro to the version specified in the vendor advisory.

Proactive Monitoring: Review database audit logs for unusual query patterns or unexpected attempts to access the query report module by standard user accounts.

Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns targeting the application endpoints.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a significant risk due to the sensitive nature of the data managed by the affected software. Security teams should prioritize patching these instances immediately to prevent unauthorized data access. If an immediate update is not feasible, restrict access to the query report module to trusted administrative personnel only until the patch is applied.

More Zohocorp CVEs

Sources