← Back to search

CVE-2026-86678

8.8 HIGH

Published 2026-09-23 · Updated 2026-09-24

AI risk analysis

Summary
This flaw allows a low-privileged user to obtain an administrator’s API key, enabling them to perform administrator-level actions, which can lead to unauthorized access and data manipulation.
Exploitability
Exploitation is relatively straightforward given the low privilege requirement, and the attacker would need access to the application to obtain the API key.
Blast radius
If exploited, the impact is high, as it could lead to unauthorized administrative actions, potentially compromising the entire system and sensitive data.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 182001 or later.
api-keyadmin-privilegedata-exposure

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-639

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.