
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3324 is an authentication bypass vulnerability in Zohocorp ManageEngine Log360 affecting builds 13000 through 13013, caused by improper filter configuration in exposed V1 APIs. The vulnerability allows unauthenticated remote attackers to bypass authorization checks on certain actions, potentially enabling unauthorized access to log data and administrative operations. It was disclosed on April 16, 2026, and a fix was released in build 13017 on March 10, 2026. The vulnerability carries a CVSS v3.1 base score of 8.2 (High) (ManageEngine Advisory, Github Advisory).
The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), where the product's filter configuration fails to enforce authentication on certain exposed V1 API endpoints. An attacker can send unauthenticated network requests directly to these V1 API paths, bypassing the authentication layer entirely due to misconfigured servlet filters or middleware that should enforce credential checks. No user interaction or prior privileges are required, and the attack complexity is low, making exploitation straightforward for any network-accessible attacker. No public proof-of-concept code has been identified at this time (ManageEngine Advisory, Github Advisory).
Successful exploitation allows unauthenticated attackers to access sensitive log data and perform administrative operations within ManageEngine Log360 without valid credentials. The primary impact is a high confidentiality breach — attackers can view security logs, audit trails, and other sensitive information managed by the SIEM platform, which may include credentials, user activity, and network event data. Integrity is also partially affected, as unauthorized operations through the V1 API may allow data manipulation, though availability is not impacted (ManageEngine Advisory, Feedly).
As of the time of disclosure, no public proof-of-concept exploit code has been observed, and there is no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.083% (24th percentile), indicating a currently low but non-negligible probability of exploitation within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Github Advisory, Feedly).
/api/v1/...) that are accessible without authentication due to the misconfigured filter./api/v1/ endpoints on the Log360 server from external or unexpected IP addresses; absence of authentication headers (e.g., Authorization, session cookies) in API requests that normally require them.Zohocorp has released a fix in ManageEngine Log360 build 13017, which resolves the authentication bypass in the exposed V1 APIs. All organizations running builds 13000 through 13013 should upgrade to build 13017 or the latest available version using the service pack as the primary remediation. As an interim measure prior to patching, organizations should restrict network access to the Log360 instance to trusted IP ranges only, implement perimeter-level authentication controls, and monitor for anomalous unauthenticated API access (ManageEngine Advisory).
The vulnerability was reported by Zoho's internal security team through the Zoho BugBounty program and disclosed publicly on April 16, 2026. Social media activity was limited, with brief mentions on Mastodon and Bluesky CVE tracking accounts shortly after disclosure. Security intelligence platforms including Horizon3.ai and Hawk-Eye published brief coverage noting the vulnerability's authentication bypass nature and the availability of a patch (ManageEngine Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."