Exposure of Google Cloud Service Account Key in ZohoCorp ManageEngine Applications Manager
CVE-2026-86708

10CRITICAL

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
23 September 2026

What is CVE-2026-86708?

The ManageEngine Applications Manager by ZohoCorp, versions 182200 and earlier, is susceptible to a vulnerability that may expose a Google Cloud service account's private key during the installation process. This weakness allows unauthorized attackers to impersonate the service account, potentially granting them access to modify or control related cloud resources. It is crucial for organizations using affected versions to implement appropriate security measures.

Affected Version(s)

ManageEngine Applications Manager 0 < 182300

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.