
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-12263 is an authentication bypass vulnerability in Zohocorp ManageEngine Password Manager Pro and PAM360 caused by improper SAML validation. It affects Password Manager Pro versions before 13232 and PAM360 versions before 8551. The vulnerability was fixed on June 9, 2026, and publicly disclosed on August 13, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (ManageEngine Advisory, GitHub Advisory).
The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature), specifically involving insufficient validation of SAML assertions during the authentication process. An attacker with low-level authenticated access can craft or manipulate SAML responses to impersonate any other user in the system, bypassing access controls. The attack is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit once an attacker has any valid account. The vulnerability is also mapped to CAPEC-475 (Signature Spoofing by Improper Validation) (ManageEngine Advisory, GitHub Advisory).
Successful exploitation allows any authenticated user to log in as any other user — including administrators — resulting in full unauthorized access to Password Manager Pro or PAM360. This grants the attacker access to stored privileged credentials, secrets, and sensitive account data managed by these platforms, with high confidentiality, integrity, and availability impact. Given that these products are privileged access management solutions, a successful attack could enable broad lateral movement across an organization's infrastructure by leveraging the credentials stored within (ManageEngine Advisory, GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" at this time. The EPSS score is approximately 0.696%, indicating a relatively low near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by security researcher 0xManhNV (ManageEngine Advisory).
NameID or subject field to reference the target user's identity. Due to improper cryptographic signature verification (CWE-347), the server fails to properly validate the integrity of the assertion.NameID values relative to the initiating session.Zohocorp released patched versions on June 9, 2026: Password Manager Pro build 13232 and PAM360 build 8551. Organizations should upgrade immediately using the official upgrade packs available at the ManageEngine download pages. As interim measures, restrict network-level access to SAML endpoints, review and validate SAML configuration settings, and monitor authentication logs for suspicious SAML-related activity. Disabling SAML-based authentication until patching is complete is also a viable temporary workaround for organizations that can tolerate the operational impact (ManageEngine Advisory).
The vulnerability received coverage from The Hacker Wire, which published an article on the ManageEngine SAML authentication bypass shortly after disclosure. Social media activity was noted on Mastodon via The Hacker Wire's account. Security intelligence platforms including VulDB, Loginsoft, and Offseq Radar also tracked and reported on the vulnerability. Overall community sentiment reflects concern given the sensitive nature of the affected products (privileged access management), though the absence of public exploits has tempered urgency somewhat.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."