8.8

CVE-2026-86678

Broken Authentication vulnerability

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerZohocorp
≫
Produkt ManageEngine Applications Manager
Default Statusunaffected
Version 0
Version < 182100
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.68% 0.504
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
0fc0942c-577d-436f-ae8e-945763c79b02 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2026-86678.html