CVE-2026-5785

HIGH

ManageEngine PAM360 < 8531 and Password Manager Pro 8600-13230 - Authenticated SQL Injection in Query Report Module

Title source: llm
STIX 2.1

Description

Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module.

Scores

CVSS v3 8.1
EPSS 0.0139
EPSS Percentile 68.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (2)
Zohocorp/ManageEngine PAM360 < 8531
Zohocorp/ManageEngine Password Manager Pro 8600 - 13230
Published Apr 16, 2026
Tracked Since Apr 16, 2026