CVE-2026-86679: Broken Access Control vulnerability
Published Sep 23, 2026
·Updated
ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.
Affected Software
1 affected component
Zohocorp ManageEngine Applications Manager<=182000
Event History
Sep 23, 2026
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A low-privileged authenticated user can exploit it. The issue affects permissions validation for deleting service monitors outside the user’s assigned scope.
2
What is the impact of successful exploitation?
An attacker can delete service monitors that are not assigned to them. The available data indicates integrity impact and limited availability impact, with no confidentiality impact.
3
Which versions are affected?
ManageEngine Applications Manager version 182000 and earlier are affected.