CVE-2026-86681 is a vulnerability in Zoho Corp Manageengine Applications Manager
Published on September 23, 2026
Broken Access Control vulnerability
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
Vulnerability Analysis
CVE-2026-86681 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a high impact on integrity, and a small impact on availability.
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2026-86681
Want to know whenever a new CVE is published for Zoho Corp Manageengine Applications Manager? stack.watch will email you.
Affected Versions
Zohocorp ManageEngine Applications Manager:- Before 182300 is affected.