CVE-2026-86708 CRITICAL

CVE-2026-86708: Sensitive data exposure

Vendor Zohocorp
Product ManageEngine Applications Manager
Weakness CWE-321
Published September 23, 2026
Last update September 24, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.

Key dates

02Disclosure timeline

September 23, 2026 CVE published
September 24, 2026 Record updated

Related vulnerabilities

04Related CVE