IM
IronMonkey Threat Research

CVE-2026-14828 HIGH

Published: 2026-09-02 | Last Modified: 2026-09-02 | Status: Received

Description

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

CVSS Metrics

Base Score: 8.8 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: 0fc0942c-577d-436f-ae8e-945763c79b02

Type: Secondary

Exploitability Score: 2.8

Impact Score: 5.9

Weaknesses

Source Type Description
0fc0942c-577d-436f-ae8e-945763c79b02 Secondary
en CWE-89
Notification
Message here