Executive Summary
A critical vulnerability (CVE-2026-86708) with a CVSS score of 10 has been discovered in ZohoCorp ManageEngine Applications Manager versions 182200 and below. This vulnerability exposes a Google Cloud service-account private key, allowing an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources. Affected organizations should update to version 182300 or later immediately.Technical Analysis
The vulnerability is caused by the exposure of a Google Cloud service-account private key in the Applications Manager installer. This allows an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources. The vulnerability is classified as CWE-321.How It Gets Exploited
An unauthenticated remote attacker can exploit this vulnerability by accessing the exposed private key in the Applications Manager installer. This allows the attacker to impersonate the service account and access or modify associated cloud resources. For example, an attacker could use the exposed private key to authenticate with the Google Cloud API and modify cloud resources.Impact Assessment
ZohoCorp ManageEngine Applications Manager versions 182200 and below are affected. An attacker can achieve high confidentiality and integrity impact, but not availability impact. The CVSS score is 10, indicating a critical vulnerability.Recommended Actions
To mitigate this vulnerability, affected organizations should update to version 182300 or later of ZohoCorp ManageEngine Applications Manager. Additionally, organizations should:- Review and monitor Google Cloud service-account activity for suspicious behavior.
- Implement additional security controls, such as restricting access to cloud resources.
Sources
- National Vulnerability Database (NVD)
- ZohoCorp ManageEngine Applications Manager security updates