CVE-2026-86678

Summary

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.

Affected Software

VendorProductVersion RangeStatus
ZohocorpManageEngine Applications Manager0 < 182100affected

Weaknesses

  • CWE-639: CWE-639 Authorization bypass through User-Controlled key

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References