SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-14828

HIGH · CVSS 8.8 EPSS 1.44%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Certain versions of Zohocorp ManageEngine Password Manager Pro, PAM360, and Access Manager Plus are susceptible to an authenticated SQL Injection vulnerability, which could allow attackers to manipulate database queries and potentially access sensitive data. Organizations using these affected products should prioritize patching to mitigate the risk of data breaches and unauthorized access. This vulnerability is particularly critical for enterprises that rely on these tools for managing credentials and access controls.

CVE
CVE-2026-14828
Severity
HIGH
CVSS
8.8
EPSS
1.44%

Original NVD Description

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.