10

CVE-2026-86708

Sensitive data exposure

ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerZohocorp
≫
Produkt ManageEngine Applications Manager
Default Statusunaffected
Version 0
Version < 182300
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.24% 0.679
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
0fc0942c-577d-436f-ae8e-945763c79b02 10 3.9 5.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CWE-321 Use of Hard-coded Cryptographic Key

The product uses a hard-coded, unchangeable cryptographic key.

https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2026-86708.html