SQL Injection Vulnerability - CVE-2026-11840

SQL Injection Vulnerability in Password Manager Pro and PAM360

CVE ID : CVE-2026-11840

Severity : High

Details :
An SQL Injection vulnerability was identified in Password Manager Pro and PAM360. The vulnerability has been addressed, and the issue does not exist in the fixed version.

Product Name Issue Affected Version(s) Fixed Version(s) Fixed On
Password Manager Pro SQL Injection Till 13231 13232 12-06-2026
PAM360 SQL Injection Till 8551 8552 12-06-2026

(Please note that this vulnerability applies to only those who have installed or upgraded to the above mentioned version)

Impact:
The SQL injection vulnerability in PAM360 and Password Manager Pro allows an adversary to craft a malicious query to execute unintended SQL operations on the database.

Steps to Upgrade:

  1. Download the latest upgrade pack from the following links
  2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above links.

Acknowledgements:

Reported by duypnh

Please contact the product support for further details at the below mentioned email addresses:

PAM360: pam360-support@manageengine.com

Password Manager Pro: passwordmanagerpro-support@manageengine.com

Get
Quote
Technical Support Request Demo