EIP-2026-109311

PRE-CVE

ManageEngine Mobile Application Manager 10 - SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109311. PoCs published by Vulnerability-Lab.

AI-analyzed exploit summary This is a vulnerability writeup detailing SQL injection flaws in ManageEngine Mobile Application Manager v10. The vulnerabilities are located in the DetailsView.do and Search.do modules, allowing remote attackers to execute SQL commands via the showMGDetails&groupId and viewName parameters.

Description

ManageEngine Mobile Application Manager 10 - SQL Injection

Exploits (1)

exploitdb WRITEUP
by Vulnerability-Lab · textwebappsphp
https://www.exploit-db.com/exploits/20172

This is a vulnerability writeup detailing SQL injection flaws in ManageEngine Mobile Application Manager v10. The vulnerabilities are located in the DetailsView.do and Search.do modules, allowing remote attackers to execute SQL commands via the showMGDetails&groupId and viewName parameters.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: ManageEngine Mobile Application Manager v10.0
No auth needed
Prerequisites: Network access to the target application · Knowledge of SQL injection techniques
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026