CVE-2026-11840

Summary

Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.

Affected Software

VendorProductVersion RangeStatus
ZohocorpManageEngine Password Manager Pro0 < 13232affected
ZohocorpManageEngine PAM3600 < 8552affected

Weaknesses

  • CWE-89: CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References