CVE-2026-86708: Sensitive data exposure
Published Sep 23, 2026
·Updated
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
Affected Software
1 affected component
Zohocorp ManageEngine Applications Manager<=182200
Event History
Sep 23, 2026
CVE Published
via MITRE·01:11 PM
Data Sourced
via MITRE·01:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
ZohoCorp ManageEngine Applications Manager versions 182200 and below are affected.
2
What does an attacker need to exploit this issue?
An attacker does not need authentication or user interaction. The exposed private key could be used to impersonate the associated Google Cloud service account.
3
What could an attacker do with the exposed key?
An attacker could access or modify cloud resources associated with the affected Google Cloud service account.