CVE-2026-86677: Broken Authentication vulnerability
Published Sep 23, 2026
·Updated
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.
Affected Software
1 affected component
Zohocorp ManageEngine Applications Manager<=182000
Event History
Sep 23, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs a low-privileged Applications Manager user account. The issue is remotely exploitable and does not require user interaction.
2
What is the potential impact?
A low-privileged user may be able to execute unauthorized SQL commands, potentially escalate to administrator access, and achieve remote code execution. Confidentiality, integrity, and availability may all be affected.
3
Which versions are affected?
ZohoCorp ManageEngine Applications Manager versions 182000 and below are affected.