{"id":"CVE-2026-86708","published":"2026-09-23T14:17:09.467","lastModified":"2026-09-24T04:18:03.367","description":"ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.","cvssScore":10,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","cwes":["CWE-321"],"vendors":[],"products":[],"references":[{"url":"https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2026-86708.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to access a Google Cloud service-account private key in the Applications Manager installer, enabling them to impersonate the service account and potentially access or modify cloud resources.","exploitability":"Exploitation is relatively easy given the unauthenticated nature and the presence of a private key in the installer. An attacker would need access to the installer file.","blast_radius":"If exploited, the impact could be significant, as it allows unauthorized access to cloud resources associated with the service account.","remediation":"Disable the Applications Manager installer feature until a patch is available or upgrade to the latest version of the Applications Manager.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","cloud","key-exposure"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:45:56.176Z"}}