CVE-2026-3324
Zoho ManageEngine Log360 vulnerability analysis and mitigation

Overview

CVE-2026-3324 is an authentication bypass vulnerability in Zohocorp ManageEngine Log360 affecting builds 13000 through 13013, caused by improper filter configuration in exposed V1 APIs. The vulnerability allows unauthenticated remote attackers to bypass authorization checks on certain actions, potentially enabling unauthorized access to log data and administrative operations. It was disclosed on April 16, 2026, and a fix was released in build 13017 on March 10, 2026. The vulnerability carries a CVSS v3.1 base score of 8.2 (High) (ManageEngine Advisory, Github Advisory).

Technical details

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), where the product's filter configuration fails to enforce authentication on certain exposed V1 API endpoints. An attacker can send unauthenticated network requests directly to these V1 API paths, bypassing the authentication layer entirely due to misconfigured servlet filters or middleware that should enforce credential checks. No user interaction or prior privileges are required, and the attack complexity is low, making exploitation straightforward for any network-accessible attacker. No public proof-of-concept code has been identified at this time (ManageEngine Advisory, Github Advisory).

Impact

Successful exploitation allows unauthenticated attackers to access sensitive log data and perform administrative operations within ManageEngine Log360 without valid credentials. The primary impact is a high confidentiality breach — attackers can view security logs, audit trails, and other sensitive information managed by the SIEM platform, which may include credentials, user activity, and network event data. Integrity is also partially affected, as unauthorized operations through the V1 API may allow data manipulation, though availability is not impacted (ManageEngine Advisory, Feedly).

Exploitability

As of the time of disclosure, no public proof-of-concept exploit code has been observed, and there is no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.083% (24th percentile), indicating a currently low but non-negligible probability of exploitation within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Github Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing ManageEngine Log360 instances running builds 13000–13013 using tools like Shodan or Censys, searching for ManageEngine Log360 web interfaces on common ports (e.g., 8080, 443).
  2. Identify exposed V1 API endpoints: Review publicly available ManageEngine Log360 API documentation or probe the target for V1 API paths (e.g., /api/v1/...) that are accessible without authentication due to the misconfigured filter.
  3. Send unauthenticated requests: Craft HTTP requests directly to the exposed V1 API endpoints without supplying authentication tokens or session cookies, bypassing the authentication layer due to the improper filter configuration.
  4. Access sensitive data or perform operations: Retrieve log data, audit records, or invoke administrative API operations that should require valid credentials, potentially exfiltrating sensitive security event information or modifying configurations (ManageEngine Advisory).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP requests to /api/v1/ endpoints on the Log360 server from external or unexpected IP addresses; absence of authentication headers (e.g., Authorization, session cookies) in API requests that normally require them.
  • Logs: Log360 access logs showing repeated API calls to V1 endpoints returning HTTP 200 responses without associated login events; anomalous access patterns to log data retrieval or administrative API functions outside of normal business hours.
  • Process/Application: Unexpected bulk export or retrieval of log records via API; administrative configuration changes not correlated with authenticated user sessions in the audit trail.

Mitigation and workarounds

Zohocorp has released a fix in ManageEngine Log360 build 13017, which resolves the authentication bypass in the exposed V1 APIs. All organizations running builds 13000 through 13013 should upgrade to build 13017 or the latest available version using the service pack as the primary remediation. As an interim measure prior to patching, organizations should restrict network access to the Log360 instance to trusted IP ranges only, implement perimeter-level authentication controls, and monitor for anomalous unauthenticated API access (ManageEngine Advisory).

Community reactions

The vulnerability was reported by Zoho's internal security team through the Zoho BugBounty program and disclosed publicly on April 16, 2026. Social media activity was limited, with brief mentions on Mastodon and Bluesky CVE tracking accounts shortly after disclosure. Security intelligence platforms including Horizon3.ai and Hawk-Eye published brief coverage noting the vulnerability's authentication bypass nature and the availability of a patch (ManageEngine Advisory).

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine Log360 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-20136CRITICAL9.8
  • Zoho ManageEngine Log360 logoZoho ManageEngine Log360
  • cpe:2.3:a:zohocorp:manageengine_log360
NoNoNov 01, 2021
CVE-2021-40177CRITICAL9.8
  • Zoho ManageEngine Log360 logoZoho ManageEngine Log360
  • cpe:2.3:a:zohocorp:manageengine_log360
NoYesAug 29, 2021
CVE-2026-3324HIGH8.2
  • Zoho ManageEngine Log360 logoZoho ManageEngine Log360
  • cpe:2.3:a:zohocorp:manageengine_log360
NoNoApr 16, 2026
CVE-2023-35785HIGH8.1
  • Zoho ManageEngine EventLog Analyzer logoZoho ManageEngine EventLog Analyzer
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesAug 28, 2023
CVE-2021-40178MEDIUM6.1
  • Zoho ManageEngine Log360 logoZoho ManageEngine Log360
  • cpe:2.3:a:zohocorp:manageengine_log360
NoYesAug 29, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management