What is CVE-2026-11840?
CVE-2026-11840 is an authenticated SQL injection vulnerability in Zohocorp ManageEngine Password Manager Pro before version 13232 and ManageEngine PAM360 before version 8552. This flaw could allow an authenticated attacker to execute unauthorized database queries. It is recommended to immediately update affected systems to the latest versions.
Azərbaycanca: CVE-2026-11840 Zohocorp-un ManageEngine Password Manager Pro (13232-dən əvvəl) və PAM360 (8552-dən əvvəl) məhsullarında autentifikasiya olunmuş SQL injection zəifliyidir. Bu boşluq autentifikasiya olunmuş istifadəçiyə verilənlər bazasına icazəsiz sorğular göndərməyə imkan verə bilər. Təsirlənən sistemləri dərhal ən son versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which ManageEngine products are affected by CVE-2026-11840?
CVE-2026-11840 affects Zohocorp's ManageEngine Password Manager Pro and ManageEngine PAM360 products.
Is authentication required to exploit CVE-2026-11840?
Yes, CVE-2026-11840 is an authenticated SQL injection vulnerability, meaning an authenticated user on the target system is required for exploitation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.