CVE-2026-3182
Received Received - Intake

Cleartext Credential Transmission in Zohocorp ManageEngine Endpoint Central

Vulnerability report for CVE-2026-3182, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: ManageEngine

Description

Zohocorp ManageEngine Endpoint Central versions beforeΒ 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
zohocorp manageengine_endpoint_central to 11.4.2528.34 (exc)
zohocorp manageengine_endpoint_central 11.4.2528.34
zohocorp manageengine_endpoint_central 11.5.2600.13

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-3182 is a privilege escalation vulnerability in Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34. It allows administrative users with limited access to view mail service configuration data created by other administrators due to improper permission checks when basic authentication is used for external mail integration.

Detection Guidance

Check if your ManageEngine Endpoint Central version is below 11.4.2528.34 or 11.5.2600.13. Review mail service configuration settings for basic authentication usage. Inspect administrative account access logs for unauthorized data view attempts.

Impact Analysis

This vulnerability could allow an attacker with administrative access to escalate privileges and view sensitive mail configuration data of other administrators. This may lead to unauthorized access to email systems or sensitive information if exploited.

Compliance Impact

This vulnerability may impact compliance with GDPR and HIPAA due to unauthorized access to sensitive mail service configuration data. Exposure of such data could lead to violations of confidentiality requirements under these regulations, particularly if personal or health-related information is involved.

Mitigation Strategies

Upgrade ManageEngine Endpoint Central to version 11.4.2528.34 or higher if using version 11.4.x. For version 11.5.x, upgrade to 11.5.2600.13. Disable basic authentication for external mail service integration if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-3182. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart