CVE-2026-86678
8.8ZohoCorp · ManageEngine Applications Manager
A low-privileged user can obtain an administrator API key in ManageEngine Applications Manager, leading to a full authorization bypass and unauthorized administrative actions.
Executive summary
A critical authorization bypass vulnerability in ManageEngine Applications Manager allows authenticated low-privileged users to escalate privileges to administrator level by harvesting API keys.
Vulnerability
The application suffers from an authorization bypass (CWE-639) where a low-privileged user can extract an administrator API key. Once obtained, this key grants the attacker the ability to perform arbitrary actions with administrative privileges.
Business impact
The ability for a low-privileged user to gain administrative control poses a severe risk to organizational data integrity and system availability. Given the CVSS score of 8.8, this vulnerability allows for complete compromise of the management server, potentially enabling lateral movement into the broader network environment.
Remediation
Immediate Action: Update ZohoCorp ManageEngine Applications Manager to version 182100 or later as specified by the vendor security advisory.
Proactive Monitoring: Audit application access logs for unusual API usage patterns, specifically focusing on administrative endpoints being accessed by non-administrative service accounts or user identities.
Compensating Controls: Implement strict network segmentation to limit access to the management interface and enforce strong API key rotation policies where possible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a high-risk security gap that effectively negates access control mechanisms within the ManageEngine environment. Administrators should prioritize patching to version 182100 immediately to prevent potential exploitation by internal malicious actors or compromised accounts.
More ZohoCorp CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section