CVE-2026-86677

8.8

ZohoCorp · ManageEngine Applications Manager

A SQL injection vulnerability in ZohoCorp ManageEngine Applications Manager allows authenticated users with low privileges to execute arbitrary SQL commands, leading to potential remote code execution.

Executive summary

A critical SQL injection vulnerability in ZohoCorp ManageEngine Applications Manager allows authenticated low-privileged users to achieve remote code execution and full system compromise.

Vulnerability

This vulnerability is classified as an SQL injection (CWE-89) flaw. It permits an authenticated user with low privileges to inject unauthorized SQL commands into the backend database, which can be leveraged to escalate privileges to administrator status and execute arbitrary code on the underlying host.

Business impact

Successful exploitation of this flaw grants an attacker complete control over the affected ManageEngine instance. Given the high CVSS score of 8.8, the potential for unauthorized data exfiltration, total system takeover, and lateral movement within the network poses a severe risk to organizational operations and data integrity.

Remediation

Immediate Action: Update ZohoCorp ManageEngine Applications Manager to version 182100 or higher immediately.

Proactive Monitoring: Review database audit logs for unusual or unauthorized query patterns originating from low-privileged user accounts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to detect and block SQL injection payloads targeting the application.

Exploitation status

Public Exploit Available: Exploit_available (false).

Analyst recommendation

The severity of this vulnerability necessitates immediate attention, as it provides a direct path to full system compromise for any authenticated user. Administrators must prioritize the deployment of the vendor-supplied patch to version 182100 to eliminate this risk. Until the update is applied, ensure that access to the application is restricted to trusted personnel only.

More ZohoCorp CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources