This document describes a security-related behavior that could allow limited access to certain mail service information under specific circumstances.
CVE ID: CVE-2026-3182
Severity: High
Fixed build:
For versions 11.4.2528.32 or below, upgrade to version 11.4.2528.34
For versions 11.5.2600.11 or below, upgrade to version 11.5.2600.13
Release date: 23 Jan 2026
Reported by: Baris via ManageEngine Bug Bounty Program
When basic authentication is used for external mail service integration, administrative users may have broader visibility into configuration data created by other administrators than originally intended. This behavior is limited to administrative access and does not affect non-admin users. It also requires a combination of conditions to be met to be impacted.
The fix for this is available in the latest build. To upgrade, follow the steps below:
For any further questions or concerns about this, please write to our support team.