# CVE-2026-86678
### Unauthorized disclosure of administrator API keys through the Applications Manager plugin.
| Vulnerability Details | |
|---|---|
| Severity | **High** |
| CVE ID | CVE-2026-86678 |
| Affected software versions | Version 182000 and below |
| Fixed Version | Version 182100 and above
Version 181104 to 181109
Version 182001 to 182009 |
| Fixed On | 26 August 2026 |
## Details
A permissions issue in an Applications Manager plugin allowed a low-privileged authenticated user to request another user’s profile and retrieve that user’s API key.
## Impact
An attacker with a low-privileged account in Applications Manager Plugin could obtain an administrator API key and use it to perform administrator-level operations, potentially gaining control of Applications Manager Plugin and accessing sensitive monitoring data.
## Fix
Applications Manager Plugin version 182100 (refer above for other fixed versions) and above fixes the vulnerability in the affected endpoint by enforcing token-based authentication.
## Steps to update
Update your Applications Manager Plugin instance to the latest build using the [service pack](https://www.manageengine.com/products/applications_manager/service-packs.html).
## Source and Acknowledgements
Find out more about CVE-2026-86678 from [CVE Directory](https://www.cve.org/CVERecord?id=CVE-2026-86678) and [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-86678).
## Reported by:
sealldev
### Need Help?
For clarification or corrections please contact our [support team](https://www.manageengine.com/products/applications_manager/support.html) or email us at [appmanager-support@manageengine.com](mailto:appmanager-support@manageengine.com).