ManageEngine security advisory—Important security fix released for ManageEngine Password Manager Pro

ManageEngine security advisory—Important security fix released for ManageEngine Password Manager Pro

Hi there,

This security advisory is to let you know that an authenticated remote code execution vulnerability was identified in Password Manager Pro. The vulnerability has been addressed, and the issue does not exist in the fixed version.

 

CVE ID: CVE-2026-18199

 

Severity : High

 

Product Name

Affected Version(s)

Fixed Version(s)

Fixed On

Password Manager Pro

Till 13235

13236

31st July, 2026

 

(Please note that this vulnerability applies to only those who have installed or upgraded to the above mentioned version)

 

Impact:
The remote code execution vulnerability allows an authenticated adversary to execute arbitrary operating-system commands.

Steps to Upgrade:

  1. Download the latest upgrade pack from the following link

  1. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above links.

 

Please contact the product support for further details at the below mentioned email addresses:

Password Manager Pro: passwordmanagerpro-support@manageengine.com


Thanks,

Dhamodhara Reddy

Head -Enterprise Support

                        New to ADSelfService Plus?