CVE-2026-3182 Details
Description
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.
A vulnerability exists in ManageEngine Endpoint Central versions prior to 11.4.2528.34, allowing for the cleartext transmission of sensitive information. This issue arises when basic authentication is used for external mail service integration, potentially exposing administrative users to configuration data from other administrators.
Users can upgrade to ManageEngine Endpoint Central version 11.4.2528.34 or 11.5.2600.13, depending on their current version. Instructions for upgrading are available in the product documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.manageengine.com/products/desktop-central/mail-configuration-data.html | ManageEngine |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | ManageEngine |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | ManageEngine |