CVE-2026-5785: SQL Injection
Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5785?
CVE-2026-5785 is classified as a critical vulnerability due to its potential for SQL injection attacks that can compromise sensitive data.
How do I fix CVE-2026-5785?
To fix CVE-2026-5785, upgrade ManageEngine PAM360 to version 8531 or later and ManageEngine Password Manager Pro to version 13231 or later.
Which versions of ManageEngine are affected by CVE-2026-5785?
CVE-2026-5785 affects ManageEngine PAM360 versions before 8531 and Password Manager Pro versions from 8600 to 13230.
What type of attack does CVE-2026-5785 allow?
CVE-2026-5785 allows for authenticated SQL injection attacks through the query report module.
Is CVE-2026-5785 known to be exploited in the wild?
As of the last update, there are no reported cases of CVE-2026-5785 being actively exploited in the wild.