Permissions Validation Flaw in ZohoCorp ManageEngine Applications Manager
CVE-2026-86679

7.1HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
23 September 2026

What is CVE-2026-86679?

A vulnerabilities exist in ZohoCorp's ManageEngine Applications Manager that permits low-privileged users to delete service monitors beyond their authorized scope. This permissions validation issue affects versions up to 182000, exposing the application to potential misuse and unauthorized actions that could disrupt service monitoring functionalities.

Affected Version(s)

ManageEngine Applications Manager 0 < 182100

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.