Permissions Validation Flaw in ZohoCorp ManageEngine Applications Manager
CVE-2026-86681

7.6HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
23 September 2026

What is CVE-2026-86681?

ZohoCorp's ManageEngine Applications Manager, in versions 182200 and earlier, contains a permissions validation flaw. This issue permits users with low privileges to execute MBean actions that are typically reserved for administrators, impacting the integrity of user assignments and the overall security of the application.

Affected Version(s)

ManageEngine Applications Manager 0 < 182300

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.