CVE-2026-11840
Zoho ManageEngine PAM360 vulnerability analysis and mitigation

Overview

CVE-2026-11840 is an authenticated SQL injection vulnerability affecting Zohocorp ManageEngine Password Manager Pro and ManageEngine PAM360. It affects Password Manager Pro versions before 13232 and PAM360 versions before 8552, with fixed versions released on June 12, 2026. The vulnerability was publicly disclosed on August 13, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (ManageEngine Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning the affected products fail to properly sanitize user-supplied input before incorporating it into SQL queries. An authenticated attacker with low-level privileges can craft malicious SQL queries over the network to manipulate the underlying database. No user interaction is required, and the attack complexity is low, making it straightforward to exploit once authenticated. The vulnerability was reported by security researcher "duypnh" (ManageEngine Advisory, GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker to read sensitive data from the database — which in the context of a password manager and privileged access management tool could include stored credentials, secrets, and privileged account data — as well as modify or delete database contents. Depending on the database configuration, attackers may also be able to execute operating system commands, potentially enabling full system compromise and lateral movement within the environment. Given that both products manage privileged credentials, a breach could expose an organization's entire privileged access infrastructure (ManageEngine Advisory, GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" at this time. The EPSS score is approximately 1.58% (74th percentile), indicating a moderate relative probability of exploitation within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication with at least low-level privileges, which limits the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible ManageEngine Password Manager Pro or PAM360 instances running versions prior to 13232 and 8552, respectively, using network scanning tools or Shodan.
  2. Authentication: Obtain valid credentials for the target application — even a low-privileged account is sufficient to exploit this vulnerability.
  3. Identify injectable parameter: Log in to the application and identify API endpoints or UI features that accept user-supplied input that is processed in database queries.
  4. Craft malicious SQL payload: Inject SQL syntax into the vulnerable parameter (e.g., using UNION-based, error-based, or blind SQL injection techniques) to manipulate the underlying database query.
  5. Extract sensitive data: Use the SQL injection to enumerate database tables and extract stored credentials, privileged account data, or other sensitive information.
  6. Escalate if possible: Depending on the database configuration (e.g., if xp_cmdshell or equivalent is enabled), attempt to execute operating system commands to achieve remote code execution and further lateral movement (ManageEngine Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: Unusual or malformed SQL-related error messages in application logs; repeated or anomalous database query patterns from authenticated low-privileged user accounts; unexpected access to sensitive database tables (e.g., credential stores) in application audit logs.
  • Network: Unexpected outbound connections from the Password Manager Pro or PAM360 server to external IPs, which may indicate OS command execution following SQL injection.
  • Process: Unusual child processes spawned by the ManageEngine application service (e.g., cmd.exe, bash, powershell) that may indicate database-level OS command execution.
  • File System: New or modified files in the ManageEngine installation directory, particularly scripts or executables not associated with normal application operation.

Mitigation and workarounds

Zohocorp has released patched versions addressing this vulnerability: Password Manager Pro build 13232 and PAM360 build 8552, both available as of June 12, 2026. Administrators should download and apply the latest upgrade pack from the official ManageEngine upgrade pages for each product. As additional hardening measures, implement network segmentation to restrict access to these management tools to authorized administrators only, and apply the principle of least privilege to service accounts running these applications (ManageEngine Advisory).

Community reactions

The vulnerability received limited but notable coverage shortly after disclosure, with aggregation by security databases including VulDB, Vulners, and ENISA's EUVD. A Mastodon post by security researcher @hugovalters noted the vulnerability. No major vendor statements beyond the official ManageEngine advisory or significant media coverage have been identified at this time.

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine PAM360 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12263HIGH8.8
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesAug 13, 2026
CVE-2026-11840HIGH8.8
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesAug 13, 2026
CVE-2024-5546HIGH8.8
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesAug 28, 2024
CVE-2026-5785HIGH8.1
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesApr 16, 2026
CVE-2025-11669HIGH8.1
  • Zoho ManageEngine Access Manager Plus logoZoho ManageEngine Access Manager Plus
  • cpe:2.3:a:zohocorp:manageengine_access_manager_plus
NoYesJan 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management