# CVE-2026-86683 ### Unauthorized modification of global proxy settings by a low-privileged user. | Vulnerability Details | | |---|---| | Severity | **High** | | CVE ID | CVE-2026-86683 | | Affected software versions | Version 182000 and below | | Fixed Version | Version 182100 and above
Version 181104 to 181109
Version 182001 to 182009 | | Fixed On | 26 August 2026 | ## Details A permissions validation issue in Applications Manager’s proxy synchronization endpoint allowed an authenticated read-only user to change the product’s proxy configuration, even though proxy administration is restricted to administrators. ## Impact An attacker could redirect Applications Manager’s outbound monitoring traffic through an attacker-controlled proxy. This could expose credentials sent by monitored HTTP services and allow monitoring responses to be manipulated, potentially affecting monitoring accuracy and system security. ## Fix Applications Manager version 182100 (refer above for other fixed versions) and above fixes this issue by enforcing proper authentication for the proxy synchronization endpoint. ## Steps to update Update your Applications Manager instance to the latest build using the service pack. ## Source and Acknowledgements Find out more about CVE-2026-86683 from [CVE Directory](https://www.cve.org/CVERecord?id=CVE-2026-86683) and [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-86683). ## Reported by: sealldev ### Need Help? For clarification or corrections please contact our [support team](https://www.manageengine.com/products/applications_manager/support.html) or email us at [appmanager-support@manageengine.com](mailto:appmanager-support@manageengine.com).