CVE-2026-14828
published 2026-09-02CVE-2026-14828: Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to…
PriorityP266high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.44%
71.5th percentile
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zohocorp | manageengine_access_manager_plus | < 4405 | 4405 |
| zohocorp | manageengine_pam360 | < 8561 | 8561 |
| zohocorp | manageengine_password_manager_pro | < 13235 | 13235 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Zohocorp Access Manager Plus/PAM360/Password Manager Pro sql injection (EUVD-2026-69888 / Nessus ID 342633)
vuldb·2026-09-04·CVSS 8.8
CVE-2026-14828 [HIGH] Zohocorp Access Manager Plus/PAM360/Password Manager Pro sql injection (EUVD-2026-69888 / Nessus ID 342633)
A vulnerability, which was classified as critical, has been found in Zohocorp Access Manager Plus, PAM360 and Password Manager Pro. This vulnerability affects unknown code. Performing a manipulation results in sql injection.
This vulnerability is cataloged as CVE-2026-14828. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerabili
ghsa_unreviewed·2026-09-02
CVE-2026-14828 [HIGH] CWE-89 Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerabili
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-02
Published