ManageEngine Applications Manager < Build 182100 Multiple Vulnerabilities

high Nessus Plugin ID 362647

Synopsis

A web application running on the remote host is affected by multiple vulnerabilities.

Description

According to its self-reported version number, the instance of ManageEngine Applications Manager running on the remote host is build 182000 or below and is not one of the fixed builds (181104 to 181109, 182001 to 182009). It is, therefore, affected by multiple vulnerabilities:

- ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.
(CVE-2026-86677)

- ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator's API key and use it to perform administrator-level actions. (CVE-2026-86678)

- ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings. (CVE-2026-86683)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to ManageEngine Applications Manager version 182100 or later, or apply the vendor-supplied fix build (181104 to 181109, or 182001 to 182009) as applicable.

See Also

http://www.nessus.org/u?17758062

http://www.nessus.org/u?a90f9aeb

http://www.nessus.org/u?d8c18307

http://www.nessus.org/u?de0100d1

Plugin Details

Severity: High

ID: 362647

File Name: manageengine_applications_manager_CVE-2026-86683.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 10/2/2026

Updated: 10/2/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.29

CVSS v2

Risk Factor: High

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-86677

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:manageengine:applications_manager

Required KB Items: installed_sw/ManageEngine Applications Manager

Patch Publication Date: 8/26/2026

Vulnerability Publication Date: 9/23/2026

Reference Information

CVE: CVE-2026-86677, CVE-2026-86678, CVE-2026-86679, CVE-2026-86683

IAVA: 2026-A-1083