CVE-2026-5785 Details
Description
Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module.
A high-severity authenticated SQL injection vulnerability has been identified in ManageEngine PAM360 versions prior to 8531 and in ManageEngine Password Manager Pro versions from 8600 to 13230. The vulnerability exists in the query report module, allowing an adversary with a Password Auditor role to execute custom SQL queries. This could lead to escalation of privileges to a Privileged Administrator, enabling the execution of sensitive actions.
Users can upgrade to ManageEngine Password Manager Pro version 13231 or ManageEngine PAM360 version 8531. Instructions for downloading the latest upgrade packs are available on the ManageEngine website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2026-5785.html | ManageEngine |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | ManageEngine |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ManageEngine |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | New CVE Received | ManageEngine |