CVE-2026-86708

10.0

Zohocorp · ManageEngine Applications Manager

ManageEngine Applications Manager installer contains a hardcoded Google Cloud service account private key, allowing unauthenticated attackers to compromise cloud resources.

Executive summary

An unauthenticated critical vulnerability in Zohocorp ManageEngine Applications Manager allows remote attackers to gain unauthorized access to Google Cloud resources via a hardcoded service account key.

Vulnerability

The application is vulnerable to CWE-321 due to the inclusion of a hardcoded cryptographic key within the installer. This flaw allows an unauthenticated attacker to impersonate the associated Google Cloud service account, granting them unauthorized access to modify or exfiltrate cloud-based data.

Business impact

The exposure of a service account key represents a severe security failure that can lead to total compromise of the affected Google Cloud environment. Given the CVSS score of 10.0, this vulnerability permits unauthenticated remote attackers to bypass identity controls, potentially resulting in massive data breaches, unauthorized modifications to infrastructure, and significant reputational damage.

Remediation

Immediate Action: Update Zohocorp ManageEngine Applications Manager to version 182300 or higher immediately to remove the hardcoded key.

Proactive Monitoring: Review Google Cloud IAM audit logs for unusual service account activity or unexpected API calls originating from the service account associated with the ManageEngine installation.

Compensating Controls: If immediate patching is not feasible, rotate the exposed Google Cloud service account keys and restrict the service account permissions to the absolute minimum necessary for operation until the update can be applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This is a critical vulnerability that requires immediate attention due to the ease of exploitation and the high impact on cloud infrastructure security. Administrators must prioritize updating to version 182300, as the presence of a hardcoded key provides a direct path for attackers to gain persistent, unauthorized access to sensitive cloud environments.

More Zohocorp CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources