CVE-2026-12263

Summary

Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.

Affected Software

VendorProductVersion RangeStatus
ZohocorpManageEngine Password Manager Pro0 < 13232affected
ZohocorpManageEngine PAM3600 < 8551affected

Weaknesses

  • CWE-347: CWE-347 Improper verification of cryptographic signature

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References