ManageEngine security advisory: Critical and high-severity security fixes released for ManageEngine Applications Manager

ManageEngine security advisory: Critical and high-severity security fixes released for ManageEngine Applications Manager

This security advisory is to let you know that one critical and five high-severity vulnerabilities were identified in ManageEngine Applications Manager. We have fixed all of them in the versions listed below.


Version details:

 

Vulnerabilities addressed

 

Affected version(s)

 

Upgrade to

CVE-2026-86708
CVE-2026-86677
CVE-2026-86678
CVE-2026-86679
CVE-2026-86681
CVE-2026-86683

181103 and below

181104

181200 to 182000

182001

182100 to 182200

182300


Vulnerability details

CVE ID

Severity

Type

Impact

CVE-2026-86708

    Critical

Sensitive Data Exposure

An attacker can access or modify cloud resources associated with Applications Manager, affecting project configuration, storage, or other cloud services.

CVE-2026-86677

      High

Broken Authentication

A low-privileged user can register an unauthorized managed server. Insufficiently protected synchronization responses may then cause the Central server to execute attacker-controlled SQL statements.

CVE-2026-86678

      High

Broken Authentication

A low-privileged user could retrieve another user's profile, including the API key.

CVE-2026-86679

      High

Broken Access Control

A low-privileged user can delete a monitored service from server monitors outside their assigned scope.

CVE-2026-86681

      High

Broken Access Control

A low-privileged user can execute an MBean action outside their assigned scope.

CVE-2026-86683

      High

Broken Authentication

A low-privileged user can modify the proxy configuration, allowing them to view monitor credentials or manipulate outbound requests.


What should customers do?

Given the severity of these vulnerabilities, customers are strongly advised to upgrade immediately. To fix all six in one go, update your build to 182300 / 182001 / 181104 (or newer), depending on your current build.

Steps to upgrade:
  1. Identify your current build number.

  2. Download the upgrade pack for your build from the Applications Manager service packs page: https://www.manageengine.com/products/applications_manager/service-packs.html

  3. Depending on your current build, one or more intermediate PPMs may be required before installing the fixed version. Follow the upgrade instructions carefully.

  4. Take a full backup of your Applications Manager installation (and back-end database) before upgrading, and keep it in a separate location.

For details on each CVE, visit the individual advisory pages on https://www.manageengine.com/products/applications_manager/security-updates.html

For assistance, contact our support team:
Toll-free: +1-888-720-9500

Please ignore this message if you have already upgraded to a fixed build. We sincerely apologize for any inconvenience this may have caused.

Regards,
ManageEngine Applications Manager Team