ZeroHour

CVE-2026-14828

large

Authenticated SQLi in ManageEngine Password Manager Pro, PAM360 and Access Manager Plus

CVSS 3.1
8.8 high
EPSS
1%p72
Published
()
Modified
AI analysis

CVE-2026-14828 is an authenticated SQL injection flaw (CWE-89) affecting three Zohocorp ManageEngine privileged-access products: Password Manager Pro, PAM360, and Access Manager Plus. An attacker who already holds low-privileged credentials on the product's web console can submit crafted input that is incorporated into a backend database query, with no user interaction required. Successful exploitation could allow reading or modifying the vault's database contents, potentially exposing vaulted credentials and account metadata (CVSS 8.8 High). Organizations running any affected build of these typically on-premises products are exposed, with internet-facing consoles at higher risk, though authentication is required. No public proof-of-concept or confirmed in-the-wild exploitation is known; the issue is not on the CISA KEV list and EPSS assigns a 1.4% probability of exploitation within 30 days.

What to do: Upgrade Password Manager Pro to build 13235 or later, PAM360 to build 8561 or later, and Access Manager Plus to build 4405 or later. Because exploitation requires an authenticated session, audit vault user accounts (remove unused or low-privilege logins), restrict network access to the web consoles, and monitor for suspicious database activity. Where immediate patching is not possible, limit console exposure to trusted networks only.

Affected
Zohocorp (ManageEngine) Password Manager ProAll builds before 13235
Zohocorp (ManageEngine) PAM360All builds before 8561
Zohocorp (ManageEngine) Access Manager PlusAll builds before 4405
Estimated exposure
large≈10,000–100,000 enterprise installations (total affected admin/operator users likely 100,000+) — Estimated from the vendor's large installed base of these on-premises privileged-access vaults, which are typically deployed one per organization and serve many privileged users, with internet-exposed consoles likely representing only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.