Executive brief
Zohocorp ManageEngine's Password Manager Pro, PAM360, and Access Manager Plus are privilege and password management platforms used to secure credentials and control privileged access in enterprise environments. An authenticated SQL injection vulnerability allows users or attackers with valid credentials to execute arbitrary database queries, potentially exposing sensitive password vaults, session logs, and administrative data stored in these systems.
Technical details
An authenticated SQL injection vulnerability exists in Password Manager Pro, PAM360, and Access Manager Plus, allowing an attacker who has valid credentials to craft malicious SQL queries and execute unintended database operations. The vulnerability requires authentication, limiting the attack surface to authorized users or compromised accounts. An attacker can exploit this to read, modify, or delete sensitive data including stored credentials, audit logs, and policy configurations. The flaw has been patched in Password Manager Pro version 13235, PAM360 version 8561, and Access Manager Plus version 4405, released on July 7, 2026.
Affected products
- Zohocorp Password Manager Pro before 13235
- Zohocorp PAM360 before 8561
- Zohocorp Access Manager Plus before 4405
Timeline
- 2026-09-02: disclosed: CVE-2026-14828 published
- 2026-07-07: patched: Fixed versions released: Password Manager Pro 13235, PAM360 8561, Access Manager Plus 4405