CVE-2026-86678
Received Received - Intake

Privilege Escalation in Zoho ManageEngine Applications Manager

Vulnerability report for CVE-2026-86678, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: ManageEngine

Description

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zoho manageengine_applications_manager to 182000 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a low-privileged user in ZohoCorp ManageEngine Applications Manager versions 182000 and below to obtain an administrator’s API key. With this key, they can perform actions that require administrator privileges, potentially leading to unauthorized access and control over the system.

Impact Analysis

If exploited, this vulnerability could allow attackers to gain full administrative access to the Applications Manager. This may result in unauthorized data access, system manipulation, or disruption of services, depending on the attacker's goals.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements such as GDPR or HIPAA. Organizations using affected versions may face legal penalties, data breaches, and loss of trust due to non-compliance with data protection regulations.

Mitigation Strategies

Update Zoho ManageEngine Applications Manager to a version higher than 182000 to address the vulnerability. Restrict low-privileged user access to sensitive API functions and review user permissions for unauthorized API key exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86678. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart