Junglewise Threat Intelligence

CVE-2026-12263: Zohocorp ManageEngine Password Manager Pro and PAM360 authentication bypass

CVE-2026-12263 · Severity: high · CVSS 8.8 · Published 2026-08-13

Vendors: Zohocorp.

Executive brief

Password Manager Pro and PAM360 are privileged access management and password storage solutions used by enterprises to centrally manage sensitive credentials. An improper SAML validation flaw allows any authenticated user to bypass authentication and log in as another user, potentially exposing all stored passwords and sensitive data to unauthorized access.

Technical details

This is an authentication bypass vulnerability caused by improper SAML validation in Password Manager Pro and PAM360. The vulnerability requires an attacker to already be an authenticated user of the system. An authenticated attacker can exploit this flaw to log in as any other user without knowing their password, effectively gaining unauthorized access to other user accounts and the sensitive data they control. The vulnerability has been patched in Password Manager Pro version 13232 and PAM360 version 8551, released on 2026-09-06.

Affected products

  • Zohocorp ManageEngine Password Manager Pro before 13232
  • Zohocorp ManageEngine PAM360 before 8551

Timeline

  • 2026-08-13: disclosed: Vulnerability published on NVD
  • 2026-09-06: patched: Fixed in Password Manager Pro 13232 and PAM360 8551

References