CVE-2026-3324 Details
Description
Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.
An authentication bypass vulnerability has been identified in ManageEngine Log360, affecting versions 13000 through 13013. This vulnerability arises from improper filter configuration, which allows certain actions to bypass authentication requirements. As a result, unauthorized users may gain access to restricted data and operations via the exposed V1 APIs.
Users can update to Log360 build 13017 or the latest version using the available service pack. Instructions for downloading the service pack are available on the ManageEngine Log360 website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.manageengine.com/log-management/advisory/CVE-2026-3324.html | ManageEngine | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | ManageEngine |
Affected Products
| Product | Versions |
|---|---|
| zohocorp manageengine log360 | 13.0 build13000 13.0 build13001 13.0 build13003 13.0 build13005 13.0 build13006 13.0 build13008 13.0 build13011 13.0 build13013 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | ManageEngine |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | New CVE Received | ManageEngine |