CVE-2026-5785
8.1Zohocorp · ManageEngine PAM360 and Password Manager Pro
Zohocorp ManageEngine PAM360 and Password Manager Pro contain an authenticated SQL injection vulnerability within the query report module.
Executive summary
An authenticated SQL injection vulnerability in Zohocorp ManageEngine PAM360 and Password Manager Pro allows an attacker to compromise sensitive database information.
Vulnerability
The application is susceptible to SQL injection (CWE-89) within the query report module, which allows an authenticated user to execute arbitrary SQL commands against the backend database.
Business impact
Successful exploitation of this vulnerability allows an authenticated attacker to read or modify sensitive data stored within the ManageEngine database. Given the nature of these products as privileged access management tools, the compromise of stored credentials and configuration data poses a critical risk to the entire organizational infrastructure. The CVSS score of 8.1 reflects the high potential for impact on confidentiality and integrity.
Remediation
Immediate Action: Upgrade ManageEngine PAM360 to version 8531 or later, and update Password Manager Pro to the version specified in the vendor advisory.
Proactive Monitoring: Review database audit logs for unusual query patterns or unexpected attempts to access the query report module by standard user accounts.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns targeting the application endpoints.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a significant risk due to the sensitive nature of the data managed by the affected software. Security teams should prioritize patching these instances immediately to prevent unauthorized data access. If an immediate update is not feasible, restrict access to the query report module to trusted administrative personnel only until the patch is applied.