CVE-2024-27312
Zoho ManageEngine PAM360 vulnerability analysis and mitigation

Overview

Zohocorp ManageEngine PAM360 version 6601 contains an authorization vulnerability that allows low-privileged users to perform administrative actions. This vulnerability specifically affects only the PAM360 6600 version, with no other versions being impacted (NVD CVE).

Technical details

The vulnerability was discovered by ManageEngine's internal security team and received a CVSS v3.1 base score of 8.1 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N. The vulnerability is classified as CWE-863 (Incorrect Authorization) and allows unauthorized access through crafted requests to the PAM360 server (Vendor Advisory).

Impact

When exploited, this vulnerability enables non-administrative users to perform privileged operations by sending crafted requests to the PAM360 server, potentially compromising the security of the system (Vendor Advisory).

Exploitability

The vulnerability can be exploited by non-admin users who have access to the system by sending specially crafted requests to the PAM360 server. Given the high severity rating and the relatively low complexity of exploitation, the risk is considered significant (Vendor Advisory).

Mitigation and workarounds

ManageEngine has released version 6601 on April 10, 2024, which addresses this vulnerability. Users are strongly advised to upgrade to the latest build immediately. The upgrade can be performed by downloading the latest upgrade pack from the official ManageEngine website and following the provided installation instructions (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine PAM360 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12263HIGH8.8
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesAug 13, 2026
CVE-2026-11840HIGH8.8
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesAug 13, 2026
CVE-2024-5546HIGH8.8
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesAug 28, 2024
CVE-2026-5785HIGH8.1
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesApr 16, 2026
CVE-2025-11669HIGH8.1
  • Zoho ManageEngine Access Manager Plus logoZoho ManageEngine Access Manager Plus
  • cpe:2.3:a:zohocorp:manageengine_access_manager_plus
NoYesJan 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management