CVE-2026-14828

Summary

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

Affected Software

VendorProductVersion RangeStatus
ZohocorpManageEngine Password Manager Pro0 < 13235affected
ZohocorpManageEngine PAM3600 < 8561affected
ZohocorpManageEngine Access Manager Plus0 < 4405affected

Weaknesses

  • CWE-89: CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References