AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-11840

HIGH · CVSS 8.8 EPSS 1.58%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

ManageEngine Password Manager Pro versions prior to 13232 and PAM360 versions before 8552 are susceptible to authenticated SQL injection vulnerabilities, allowing attackers to manipulate database queries and potentially access sensitive information. This high-severity flaw (CVSS 8.8) poses a significant risk to organizations using these products, particularly those managing critical credentials and secrets. Organizations utilizing these versions should prioritize immediate updates to mitigate potential data breaches.

CVE
CVE-2026-11840
Severity
HIGH
CVSS
8.8
EPSS
1.58%

Original NVD Description

Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.