CVE-2026-5785
Zoho ManageEngine PAM360 vulnerability analysis and mitigation

Overview

CVE-2026-5785 is an authenticated SQL injection vulnerability in the query report module of Zohocorp ManageEngine PAM360 and ManageEngine Password Manager Pro. It affects PAM360 versions before 8531 and Password Manager Pro versions from 8600 to 13230. The vulnerability was disclosed on April 16, 2026, with fixes released by Zohocorp on April 2, 2026 (PAM360) and April 7, 2026 (Password Manager Pro). It carries a CVSS v3.1 base score of 8.1 (High) (ManageEngine Advisory, Github Advisory).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), arising from insufficient sanitization of user-supplied input in the query report module. An authenticated attacker with low privileges — specifically a user holding the Password Auditor role — can inject malicious SQL syntax into query parameters, causing the application to execute arbitrary SQL commands against the backend database. No user interaction is required, and the attack is conducted remotely over the network with low complexity (ManageEngine Advisory, Github Advisory).

Impact

Successful exploitation allows an attacker with a Password Auditor role to execute custom SQL queries, escalate privileges to Privileged Administrator, and perform sensitive administrative actions. This can result in exfiltration of stored credentials managed by PAM360 or Password Manager Pro, unauthorized modification of database records, and potential compromise of administrative accounts. Given that these products manage privileged credentials across enterprise infrastructure, a successful attack could enable broad lateral movement and systemic compromise of connected systems (ManageEngine Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.022–0.028%, placing it in a low percentile for near-term exploitation probability. The vulnerability was reported by security researcher Fabius Watson and disclosed responsibly to Zohocorp (ManageEngine Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible ManageEngine PAM360 (versions before 8531) or Password Manager Pro (versions 8600–13230) instances.
  2. Obtain low-privileged access: Authenticate to the application using an account with the Password Auditor role — a low-privilege role that may be granted to auditors or non-administrative staff.
  3. Navigate to the query report module: Access the query report functionality within the application, which is the vulnerable component accepting user-controlled input.
  4. Inject malicious SQL payload: Craft and submit SQL injection payloads within query parameters of the report module (e.g., appending ' OR 1=1--, UNION-based, or stacked queries) to manipulate the underlying SQL command.
  5. Escalate privileges: Leverage the SQL injection to read or modify database records, including those governing user roles, to escalate from Password Auditor to Privileged Administrator.
  6. Exfiltrate credentials or perform administrative actions: With elevated access, extract stored privileged credentials, modify configurations, or perform sensitive administrative operations across the managed infrastructure (ManageEngine Advisory).

Indicators of compromise

  • Logs: Unusual or malformed SQL-like strings in application access logs for the query report module endpoint; repeated query submissions from a single low-privileged account in a short timeframe.
  • Database: Unexpected queries involving UNION, OR 1=1, comment sequences (--), or stacked statements in database query logs; unauthorized reads or modifications to user role or credential tables.
  • Application Behavior: Unexpected privilege escalation events where a Password Auditor account gains Privileged Administrator access; anomalous administrative actions performed by accounts not normally authorized.
  • Network: Unusual outbound connections from the PAM360 or Password Manager Pro server following query report activity, potentially indicating data exfiltration.

Mitigation and workarounds

Zohocorp has released fixed versions addressing this vulnerability: PAM360 version 8531 (released April 2, 2026) and Password Manager Pro version 13231 (released April 7, 2026). Organizations should upgrade immediately using the upgrade packs available at the official ManageEngine upgrade pages. As interim mitigations, restrict access to the query report module to only authorized administrative users, implement network segmentation to limit exposure of these applications, and apply the principle of least privilege for application database accounts. Monitor database activity for suspicious SQL patterns (ManageEngine Advisory).

Community reactions

The vulnerability received standard coverage across CVE tracking platforms and threat intelligence aggregators shortly after disclosure on April 16, 2026, including mentions on Bluesky CVE feeds and weekly threat landscape digests. No notable vendor statements beyond the official Zohocorp advisory or significant independent researcher commentary have been identified. Community reaction has been measured, consistent with the absence of public exploits and the relatively narrow exploitation precondition of requiring authenticated access.

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine PAM360 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12263HIGH8.8
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesAug 13, 2026
CVE-2026-11840HIGH8.8
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesAug 13, 2026
CVE-2024-5546HIGH8.8
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesAug 28, 2024
CVE-2026-5785HIGH8.1
  • Zoho ManageEngine PAM360 logoZoho ManageEngine PAM360
  • cpe:2.3:a:zohocorp:manageengine_pam360
NoYesApr 16, 2026
CVE-2025-11669HIGH8.1
  • Zoho ManageEngine Access Manager Plus logoZoho ManageEngine Access Manager Plus
  • cpe:2.3:a:zohocorp:manageengine_access_manager_plus
NoYesJan 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management