Sceawere
Vulnerability Detail
CVE-2026-12263UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ManageEngine SAML Authentication Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 10h ago
- Vendor
- Zohocorp
- Product
- ManageEngine Password Manager Pro
- Attack Type
- CWE-347 Improper verification of cryptographic signature
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-13T11:17:38.193Z",
"pubdate": "2026-08-13T11:17:38.193Z",
"executiveSummary": "An authentication bypass vulnerability has been identified in Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551.\nThe vulnerability stems from improper validation of Security Assertion Markup Language (SAML) responses within the application's single sign-on (SSO) implementation.\nSuccessful exploitation of this flaw allows unauthenticated remote attackers to bypass authentication mechanisms entirely and gain unauthorized access to vulnerable systems.\nGiven that both products are privileged access management (PAM) solutions protecting critical enterprise credentials and infrastructure, this vulnerability introduces severe risk implications, potentially leading to total compromise of the managed environment.\nAttackers do not require prior credentials or privileged access to execute the attack, relying solely on manipulating SAML assertions accepted by the misconfigured authentication validation routines.\nOrganizations deploying the affected versions of Zohocorp ManageEngine Password Manager Pro and PAM360 are at critical risk until appropriate patches are applied.",
"technicalDetails": "The root cause of the vulnerability resides in the cryptographic or logical validation logic handling SAML responses during the authentication process within the affected Zohocorp ManageEngine products.\nSpecifically, improper SAML validation fails to properly verify signature integrity, assertion validity periods, or issuer authenticity, allowing maliciously crafted or manipulated SAML assertions to be processed as valid by the application.\nThe vulnerable component is the SAML single sign-on module responsible for parsing and validating assertions received from Identity Providers (IdPs).\nAffected software includes Zohocorp ManageEngine Password Manager Pro versions prior to 13232 and PAM360 versions prior to 8551.\nThe attack flow proceeds as follows: An unauthenticated attacker interacts with the SAML SSO login endpoint exposed over the network. Instead of presenting valid credentials, the attacker crafts or modifies a SAML response payload to assert an arbitrary user identity, often with administrative privileges. Due to the lack of stringent validation checks on the incoming assertion—such as missing signature verification or insecure XML parsing—the application accepts the forged SAML response without validating its authenticity against the trusted IdP public key.\nConsequently, the application establishes a valid user session for the specified identity, effectively bypassing standard authentication controls.\nNo authentication or privilege requirements are needed by the attacker to initiate this attack vector, and network exposure is present wherever the SAML SSO login interface is accessible.\nPost-exploitation impact includes full administrative control over the Password Manager Pro or PAM360 instance, enabling the extraction of stored credentials, manipulation of security policies, and potential lateral movement across the broader enterprise network."
}