Remote Code Execution Vulnerability in Password Manager Pro and PAM360

Remote Code Execution Vulnerability in Password Manager Pro and PAM360

Severity : High

CVE ID : CVE-2026-18199

Details :
An authenticated remote code execution vulnerability was identified in Password Manager Pro and PAM360. The vulnerability has been addressed, and the issue does not exist in the fixed version.

Product Name Affected Version(s) Fixed Version(s) Fixed On
Password Manager Pro Till 13235 13236 31st July, 2026
PAM360 Till 8600 8601 30th July, 2026

We fixed the issue by adding proper validation and escaping special characters on the server side.

Impact:
The remote code execution vulnerability allows an authenticated adversary to execute arbitrary operating-system commands.

Steps to Upgrade:

  1. Download the latest upgrade pack from the following links for the respective products:
  2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above links.

Please contact the product support for further details at the below mentioned email addresses:

PAM360: pam360-support@manageengine.com

Password Manager Pro: passwordmanagerpro-support@manageengine.com

Get
Quote
Technical Support Request Demo