CVE-2026-12263
HIGHCVSS 8.8/10EPSS 0.70%
Last modified
CVE-2026-12263 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | ManageEngine Password Manager Pro | < 13232 |
| Zohocorp | ManageEngine PAM360 | < 8551 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-12263?
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
How severe is CVE-2026-12263?
CVE-2026-12263 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.70% probability of exploitation in the next 30 days.
How do I fix CVE-2026-12263?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12256Contributor PHP Object Injection in Avada <= 3.15.3 versions…8.8
- CVE-2026-12257Versions of Mura CMS prior to 10.0.712 contain a critical re…9.3
- CVE-2026-12258Inadequate access control in Hiperdino’s REST v1.0 API. The …9.2
- CVE-2026-12259In nltk version 3.9.4, the `nltk.downloader.Downloader._down…5.3
- CVE-2026-1226CWE‑94: Improper Control of Generation of Code vulnerability…7
- CVE-2026-12261A vulnerability in `nltk.downloader` in nltk/nltk versions <…6.5
- CVE-2026-1227CWE-611: Improper Restriction of XML External Entity Referen…7
- CVE-2026-12270The Everest Forms WordPress plugin before 3.5.0 does not co…6.5
- CVE-2026-12271The Tutor LMS WordPress plugin before 3.9.13 does not verif…5.4
- CVE-2026-12273The Tutor LMS WordPress plugin before 3.9.13 does not perfo…4.3
- CVE-2026-12274The Tutor LMS WordPress plugin before 3.9.13 does not verif…6.5
- CVE-2026-12275The Tutor LMS WordPress plugin before 3.9.13 does not, in i…7.1
Are you affected by CVE-2026-12263?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
