{"id":"CVE-2026-86677","published":"2026-09-23T14:17:08.803","lastModified":"2026-09-24T04:18:03.010","description":"ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2026-86677.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw allows a low-privileged user to execute unauthorized SQL commands, potentially gaining full administrative access and remote code execution, which can lead to complete compromise of the affected system.","exploitability":"Exploitation is relatively straightforward given that a low-privileged user can initiate the attack, but requires the application to be misconfigured or have certain features enabled.","blast_radius":"If exploited, the impact is severe as it can result in unauthorized access and control over the entire system, leading to data theft, system damage, or further attacks.","remediation":"Upgrade to ManageEngine Applications Manager version 182001 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","sql-injection","web","auth-bypass"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:57:33.692Z"}}