Hi there,
This security advisory is to let you know that an authenticated remote code execution vulnerability was identified in Password Manager Pro. The vulnerability has been addressed, and the issue does not exist in the fixed version.
CVE ID: CVE-2026-18199
Severity : High
Product Name | Affected Version(s) | Fixed Version(s) | Fixed On |
Password Manager Pro | Till 13235 | 13236 | 31st July, 2026 |
(Please note that this vulnerability applies to only those who have installed or upgraded to the above mentioned version)
Impact:
The remote code execution vulnerability allows an authenticated adversary to execute arbitrary operating-system commands.
Steps to Upgrade:
Download the latest upgrade pack from the following link
Password Manager Pro - https://www.manageengine.com/products/passwordmanagerpro/minor-upgrades.html
Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above links.
Please contact the product support for further details at the below mentioned email addresses:
Password Manager Pro: passwordmanagerpro-support@manageengine.com
Thanks,
Dhamodhara Reddy
Head -Enterprise Support