CVE-2026-86678: Broken Authentication vulnerability
Published Sep 23, 2026
·Updated
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
Affected Software
1 affected component
Zohocorp ManageEngine Applications Manager<=182000
Event History
Sep 23, 2026
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs a low-privileged user account in ManageEngine Applications Manager. No user interaction is required.
2
Which versions are affected?
ManageEngine Applications Manager version 182000 and earlier are affected.
3
What is the impact if exploitation succeeds?
A low-privileged user can obtain an administrator API key and use it to perform administrator-level actions, affecting confidentiality, integrity, and availability.