CVE-2026-12263: Authentication Bypass
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ManageEngine Password Manager Proto a version that resolves this vulnerability.Fixed in 13232 - Upgrade
Upgrade
PAM360to a version that resolves this vulnerability.Fixed in 8551
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12263?
CVE-2026-12263 has a severity score of 8.8, indicating it is a high-risk vulnerability.
What type of vulnerability is CVE-2026-12263?
CVE-2026-12263 is an authentication bypass vulnerability due to improper SAML validation.
How do I fix CVE-2026-12263?
To fix CVE-2026-12263, upgrade to ManageEngine Password Manager Pro version 13232 or later, or PAM360 version 8551 or later.
What products are affected by CVE-2026-12263?
CVE-2026-12263 affects ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551.
When was CVE-2026-12263 published?
CVE-2026-12263 was published on August 13, 2026.