cbcvebase.
CVE-2026-11840
published 2026-08-13

CVE-2026-11840: Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.

PriorityP262high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.58%
74.1th percentile
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.

Affected

2 ranges
VendorProductVersion rangeFixed in
zohocorpmanageengine_pam360< 85528552
zohocorpmanageengine_password_manager_pro< 1323213232
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.