
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11840 is an authenticated SQL injection vulnerability affecting Zohocorp ManageEngine Password Manager Pro and ManageEngine PAM360. It affects Password Manager Pro versions before 13232 and PAM360 versions before 8552, with fixed versions released on June 12, 2026. The vulnerability was publicly disclosed on August 13, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (ManageEngine Advisory, GitHub Advisory).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning the affected products fail to properly sanitize user-supplied input before incorporating it into SQL queries. An authenticated attacker with low-level privileges can craft malicious SQL queries over the network to manipulate the underlying database. No user interaction is required, and the attack complexity is low, making it straightforward to exploit once authenticated. The vulnerability was reported by security researcher "duypnh" (ManageEngine Advisory, GitHub Advisory).
Successful exploitation allows an authenticated attacker to read sensitive data from the database — which in the context of a password manager and privileged access management tool could include stored credentials, secrets, and privileged account data — as well as modify or delete database contents. Depending on the database configuration, attackers may also be able to execute operating system commands, potentially enabling full system compromise and lateral movement within the environment. Given that both products manage privileged credentials, a breach could expose an organization's entire privileged access infrastructure (ManageEngine Advisory, GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" at this time. The EPSS score is approximately 1.58% (74th percentile), indicating a moderate relative probability of exploitation within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication with at least low-level privileges, which limits the attack surface compared to unauthenticated vulnerabilities.
xp_cmdshell or equivalent is enabled), attempt to execute operating system commands to achieve remote code execution and further lateral movement (ManageEngine Advisory, GitHub Advisory).cmd.exe, bash, powershell) that may indicate database-level OS command execution.Zohocorp has released patched versions addressing this vulnerability: Password Manager Pro build 13232 and PAM360 build 8552, both available as of June 12, 2026. Administrators should download and apply the latest upgrade pack from the official ManageEngine upgrade pages for each product. As additional hardening measures, implement network segmentation to restrict access to these management tools to authorized administrators only, and apply the principle of least privilege to service accounts running these applications (ManageEngine Advisory).
The vulnerability received limited but notable coverage shortly after disclosure, with aggregation by security databases including VulDB, Vulners, and ENISA's EUVD. A Mastodon post by security researcher @hugovalters noted the vulnerability. No major vendor statements beyond the official ManageEngine advisory or significant media coverage have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."