This security advisory is to let you know that one critical and five high-severity vulnerabilities were identified in ManageEngine Applications Manager. We have fixed all of them in the versions listed below.
Version details:
Vulnerabilities addressed |
Affected version(s) |
Upgrade to |
CVE-2026-86708 | 181103 and below | |
181200 to 182000 | ||
182100 to 182200 |
Vulnerability details
CVE ID | Severity | Type | Impact |
Critical | Sensitive Data Exposure | An attacker can access or modify cloud resources associated with Applications Manager, affecting project configuration, storage, or other cloud services. | |
High | Broken Authentication | A low-privileged user can register an unauthorized managed server. Insufficiently protected synchronization responses may then cause the Central server to execute attacker-controlled SQL statements. | |
High | Broken Authentication | A low-privileged user could retrieve another user's profile, including the API key. | |
High | Broken Access Control | A low-privileged user can delete a monitored service from server monitors outside their assigned scope. | |
High | Broken Access Control | A low-privileged user can execute an MBean action outside their assigned scope. | |
High | Broken Authentication | A low-privileged user can modify the proxy configuration, allowing them to view monitor credentials or manipulate outbound requests. |
What should customers do?
Given the severity of these vulnerabilities, customers are strongly advised to upgrade immediately. To fix all six in one go, update your build to 182300 / 182001 / 181104 (or newer), depending on your current build.
Identify your current build number.
Download the upgrade pack for your build from the Applications Manager service packs page: https://www.manageengine.com/products/applications_manager/service-packs.html
Depending on your current build, one or more intermediate PPMs may be required before installing the fixed version. Follow the upgrade instructions carefully.
Take a full backup of your Applications Manager installation (and back-end database) before upgrading, and keep it in a separate location.
Please ignore this message if you have already upgraded to a fixed build. We sincerely apologize for any inconvenience this may have caused.