Sceawere

Vulnerability Detail

CVE-2026-14828UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ManageEngine Authenticated SQL Injection

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
22h ago
Vendor
Zohocorp
Product
ManageEngine Password Manager Pro
Attack Type
CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-02T08:16:42.833Z",
  "pubdate": "2026-09-02T08:16:42.833Z",
  "executiveSummary": "A critical security vulnerability involving authenticated SQL Injection has been identified in Zohocorp ManageEngine Password Manager Pro (prior to 13235), PAM360 (prior to 8561), and Access Manager Plus (prior to 4405).\nThe vulnerability arises from insufficient sanitization of user-supplied input before it is incorporated into database queries.\nThis flaw allows an authenticated attacker to manipulate backend SQL queries, potentially leading to unauthorized data exfiltration, modification of database content, or interference with application logic.\nThe exploitation requires the attacker to possess valid authentication credentials within the target application. Given the nature of these products, which manage highly sensitive credentials and privileged access, successful exploitation poses a significant risk to the integrity and confidentiality of the organization's managed secrets and security infrastructure.\nThe risk is mitigated by updating the respective software versions to the remediated releases provided by Zohocorp.",
  "technicalDetails": "The vulnerability is characterized as an SQL Injection (SQLi) flaw within the application's backend database interaction layer. It stems from the application's failure to properly parameterize or sanitize user-supplied input before passing it to the database engine.\nAn authenticated attacker can leverage this flaw by injecting malicious SQL commands into input fields that are inadequately protected. When the application processes the tainted input, it inadvertently executes the injected SQL statements within the context of the database service account.\nThe exploitation flow typically begins with an authenticated user identifying an application interface that interacts with the backend database. By intercepting and modifying the parameters sent in a request—such as those found in HTTP GET or POST requests—the attacker can break out of the intended query structure. By appending SQL syntax, such as UNION, OR, or stacked queries, the attacker can manipulate the query logic.\nSuccessful exploitation allows the attacker to bypass access controls, retrieve data from sensitive tables containing credentials or administrative user information, or modify the database state. In some configurations, if the database permissions are misconfigured or overly permissive, the injection may facilitate broader impact, including administrative control over the database management system itself.\nAffected software versions include ManageEngine Password Manager Pro before 13235, PAM360 before 8561, and Access Manager Plus before 4405. The vulnerability resides within the application modules responsible for handling user requests and performing database operations. Exploitation requires that the attacker has already obtained valid session credentials, meaning this is an authenticated-level risk that can be exploited by an insider or an attacker who has previously compromised a low-privileged account.\nThe technical impact is severe because these products are designed to serve as central repositories for sensitive credentials, keys, and privileged access management (PAM). A compromise of the underlying database through SQL injection effectively provides the attacker with access to the entirety of the managed secrets vault, fundamentally undermining the security architecture of the enterprise network where these tools are deployed."
}
CVE-2026-14828: ManageEngine Authenticated SQL Injection (HIGH Severity, CVSS: 8.8) - Sceawere