← Back to search

CVE-2026-86677

8.8 HIGH

Published 2026-09-23 · Updated 2026-09-24

AI risk analysis

Summary
This flaw allows a low-privileged user to execute unauthorized SQL commands, potentially gaining full administrative access and remote code execution, which can lead to complete compromise of the affected system.
Exploitability
Exploitation is relatively straightforward given that a low-privileged user can initiate the attack, but requires the application to be misconfigured or have certain features enabled.
Blast radius
If exploited, the impact is severe as it can result in unauthorized access and control over the entire system, leading to data theft, system damage, or further attacks.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to ManageEngine Applications Manager version 182001 or later.
rcesql-injectionwebauth-bypass

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.