CVE-2026-14828
largeAuthenticated SQLi in ManageEngine Password Manager Pro, PAM360 and Access Manager Plus
CVE-2026-14828 is an authenticated SQL injection flaw (CWE-89) affecting three Zohocorp ManageEngine privileged-access products: Password Manager Pro, PAM360, and Access Manager Plus. An attacker who already holds low-privileged credentials on the product's web console can submit crafted input that is incorporated into a backend database query, with no user interaction required. Successful exploitation could allow reading or modifying the vault's database contents, potentially exposing vaulted credentials and account metadata (CVSS 8.8 High). Organizations running any affected build of these typically on-premises products are exposed, with internet-facing consoles at higher risk, though authentication is required. No public proof-of-concept or confirmed in-the-wild exploitation is known; the issue is not on the CISA KEV list and EPSS assigns a 1.4% probability of exploitation within 30 days.
What to do: Upgrade Password Manager Pro to build 13235 or later, PAM360 to build 8561 or later, and Access Manager Plus to build 4405 or later. Because exploitation requires an authenticated session, audit vault user accounts (remove unused or low-privilege logins), restrict network access to the web consoles, and monitor for suspicious database activity. Where immediate patching is not possible, limit console exposure to trusted networks only.
| Zohocorp (ManageEngine) Password Manager Pro | All builds before 13235 |
| Zohocorp (ManageEngine) PAM360 | All builds before 8561 |
| Zohocorp (ManageEngine) Access Manager Plus | All builds before 4405 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.