
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5785 is an authenticated SQL injection vulnerability in the query report module of Zohocorp ManageEngine PAM360 and ManageEngine Password Manager Pro. It affects PAM360 versions before 8531 and Password Manager Pro versions from 8600 to 13230. The vulnerability was disclosed on April 16, 2026, with fixes released by Zohocorp on April 2, 2026 (PAM360) and April 7, 2026 (Password Manager Pro). It carries a CVSS v3.1 base score of 8.1 (High) (ManageEngine Advisory, Github Advisory).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), arising from insufficient sanitization of user-supplied input in the query report module. An authenticated attacker with low privileges — specifically a user holding the Password Auditor role — can inject malicious SQL syntax into query parameters, causing the application to execute arbitrary SQL commands against the backend database. No user interaction is required, and the attack is conducted remotely over the network with low complexity (ManageEngine Advisory, Github Advisory).
Successful exploitation allows an attacker with a Password Auditor role to execute custom SQL queries, escalate privileges to Privileged Administrator, and perform sensitive administrative actions. This can result in exfiltration of stored credentials managed by PAM360 or Password Manager Pro, unauthorized modification of database records, and potential compromise of administrative accounts. Given that these products manage privileged credentials across enterprise infrastructure, a successful attack could enable broad lateral movement and systemic compromise of connected systems (ManageEngine Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.022–0.028%, placing it in a low percentile for near-term exploitation probability. The vulnerability was reported by security researcher Fabius Watson and disclosed responsibly to Zohocorp (ManageEngine Advisory).
' OR 1=1--, UNION-based, or stacked queries) to manipulate the underlying SQL command.Zohocorp has released fixed versions addressing this vulnerability: PAM360 version 8531 (released April 2, 2026) and Password Manager Pro version 13231 (released April 7, 2026). Organizations should upgrade immediately using the upgrade packs available at the official ManageEngine upgrade pages. As interim mitigations, restrict access to the query report module to only authorized administrative users, implement network segmentation to limit exposure of these applications, and apply the principle of least privilege for application database accounts. Monitor database activity for suspicious SQL patterns (ManageEngine Advisory).
The vulnerability received standard coverage across CVE tracking platforms and threat intelligence aggregators shortly after disclosure on April 16, 2026, including mentions on Bluesky CVE feeds and weekly threat landscape digests. No notable vendor statements beyond the official Zohocorp advisory or significant independent researcher commentary have been identified. Community reaction has been measured, consistent with the absence of public exploits and the relatively narrow exploitation precondition of requiring authenticated access.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."