CVE-2026-12263
Zoho ManageEngine PAM360 vulnerability analysis and mitigation

Overview

CVE-2026-12263 is an authentication bypass vulnerability in Zohocorp ManageEngine Password Manager Pro and PAM360 caused by improper SAML validation. It affects Password Manager Pro versions before 13232 and PAM360 versions before 8551. The vulnerability was fixed on June 9, 2026, and publicly disclosed on August 13, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (ManageEngine Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature), specifically involving insufficient validation of SAML assertions during the authentication process. An attacker with low-level authenticated access can craft or manipulate SAML responses to impersonate any other user in the system, bypassing access controls. The attack is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit once an attacker has any valid account. The vulnerability is also mapped to CAPEC-475 (Signature Spoofing by Improper Validation) (ManageEngine Advisory, GitHub Advisory).

Impact

Successful exploitation allows any authenticated user to log in as any other user — including administrators — resulting in full unauthorized access to Password Manager Pro or PAM360. This grants the attacker access to stored privileged credentials, secrets, and sensitive account data managed by these platforms, with high confidentiality, integrity, and availability impact. Given that these products are privileged access management solutions, a successful attack could enable broad lateral movement across an organization's infrastructure by leveraging the credentials stored within (ManageEngine Advisory, GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" at this time. The EPSS score is approximately 0.696%, indicating a relatively low near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by security researcher 0xManhNV (ManageEngine Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible instances of ManageEngine Password Manager Pro (versions before 13232) or PAM360 (versions before 8551) with SAML authentication enabled.
  2. Obtain low-privilege access: Acquire any valid user account on the target system — this vulnerability requires at least low-level authenticated access.
  3. Intercept or craft SAML response: Using a tool such as Burp Suite, intercept the SAML authentication flow or craft a SAML response targeting a privileged user (e.g., an administrator account).
  4. Manipulate SAML assertion: Modify the SAML assertion's NameID or subject field to reference the target user's identity. Due to improper cryptographic signature verification (CWE-347), the server fails to properly validate the integrity of the assertion.
  5. Submit forged SAML response: Submit the manipulated SAML response to the application's SAML assertion consumer service (ACS) endpoint.
  6. Gain unauthorized access: The application accepts the forged assertion and authenticates the attacker as the impersonated user, granting full access to that user's account and all stored privileged credentials (ManageEngine Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: Authentication log entries showing a user logging in via SAML from an unexpected IP address or at an unusual time; multiple SAML authentication events for high-privilege accounts originating from a single low-privilege user's session.
  • Logs: Application logs showing SAML assertion consumer service (ACS) endpoint requests with mismatched or anomalous NameID values relative to the initiating session.
  • Network: Unexpected SAML POST requests to the ACS endpoint from internal hosts that do not normally initiate SAML flows; unusual access patterns to privileged credential vaults shortly after SAML authentication events.
  • Behavioral: Administrative actions (credential exports, user management changes, policy modifications) performed by accounts that do not normally perform such actions, particularly following SAML login events.

Mitigation and workarounds

Zohocorp released patched versions on June 9, 2026: Password Manager Pro build 13232 and PAM360 build 8551. Organizations should upgrade immediately using the official upgrade packs available at the ManageEngine download pages. As interim measures, restrict network-level access to SAML endpoints, review and validate SAML configuration settings, and monitor authentication logs for suspicious SAML-related activity. Disabling SAML-based authentication until patching is complete is also a viable temporary workaround for organizations that can tolerate the operational impact (ManageEngine Advisory).

Community reactions

The vulnerability received coverage from The Hacker Wire, which published an article on the ManageEngine SAML authentication bypass shortly after disclosure. Social media activity was noted on Mastodon via The Hacker Wire's account. Security intelligence platforms including VulDB, Loginsoft, and Offseq Radar also tracked and reported on the vulnerability. Overall community sentiment reflects concern given the sensitive nature of the affected products (privileged access management), though the absence of public exploits has tempered urgency somewhat.

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine PAM360 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12263HIGH8.8
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesAug 13, 2026
CVE-2026-11840HIGH8.8
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesAug 13, 2026
CVE-2024-5546HIGH8.8
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesAug 28, 2024
CVE-2026-5785HIGH8.1
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesApr 16, 2026
CVE-2025-11669HIGH8.1
  • Zoho ManageEngine Access Manager Plus logoZoho ManageEngine Access Manager Plus
  • cpe:2.3:a:zohocorp:manageengine_access_manager_plus
NoYesJan 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management