Privilege Escalation Vulnerability in ZohoCorp ManageEngine Applications Manager
CVE-2026-86678
8.8HIGH
What is CVE-2026-86678?
A significant security flaw in ZohoCorp's ManageEngine Applications Manager versions 182000 and earlier permits low-privileged users to obtain an administrator’s API key. This key can be exploited to execute administrator-level actions, potentially compromising the integrity and confidentiality of the application. Organizations using affected versions are advised to upgrade to secure their systems.
Affected Version(s)
ManageEngine Applications Manager 0 < 182100