CVE-2026-14828: SQL Injection
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zohocorp ManageEngine Password Manager Proto a version that resolves this vulnerability.Fixed in 13235 - Upgrade
Upgrade
PAM360to a version that resolves this vulnerability.Fixed in 8561 - Upgrade
Upgrade
Access Manager Plusto a version that resolves this vulnerability.Fixed in 4405
Event History
Frequently Asked Questions
Which deployments are affected?
ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are affected.
What level of access does an attacker need?
An attacker needs authenticated access with low privileges. The vulnerability is network-accessible and does not require user interaction.
What is the potential impact of exploitation?
Successful exploitation can affect confidentiality, integrity, and availability at a high level.