CVE-2026-11840: SQL Injection
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ManageEngine Password Manager Proto a version that resolves this vulnerability.Fixed in 13232 - Upgrade
Upgrade
ManageEngine PAM360to a version that resolves this vulnerability.Fixed in 8552
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11840?
The severity of CVE-2026-11840 is rated high with a score of 8.8.
What type of vulnerability is CVE-2026-11840?
CVE-2026-11840 is an SQL injection vulnerability.
How does CVE-2026-11840 affect Zohocorp ManageEngine Password Manager Pro?
CVE-2026-11840 allows authenticated users to execute arbitrary SQL queries in the affected versions.
How do I fix CVE-2026-11840?
To fix CVE-2026-11840, upgrade to ManageEngine Password Manager Pro version 13232 or later and PAM360 version 8552 or later.
What systems are impacted by CVE-2026-11840?
CVE-2026-11840 impacts Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552.