CVE-2026-86683: Broken Authentication Vulnerability
Published Sep 23, 2026
·Updated
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.
Affected Software
1 affected component
Zohocorp ManageEngine Applications Manager<=182000
Event History
Sep 23, 2026
CVE Published
via MITRE·01:23 PM
Data Sourced
via MITRE·01:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must already have a low-privileged user account in ManageEngine Applications Manager. The issue is remotely reachable and does not require user interaction.
2
Which versions are affected?
ManageEngine Applications Manager version 182000 and earlier are affected.
3
What could an attacker do?
A low-privileged user could change the proxy settings. The supplied severity vector indicates potential high impact to confidentiality and integrity, with no stated availability impact.