Severity : High
CVE ID : CVE-2026-18199
Details :
An authenticated remote code execution vulnerability was identified in Password Manager Pro and PAM360. The vulnerability has been addressed, and the issue does not exist in the fixed version.
| Product Name | Affected Version(s) | Fixed Version(s) | Fixed On |
|---|---|---|---|
| Password Manager Pro | Till 13235 | 13236 | 31st July, 2026 |
| PAM360 | Till 8600 | 8601 | 30th July, 2026 |
We fixed the issue by adding proper validation and escaping special characters on the server side.
Impact:
The remote code execution vulnerability allows an authenticated adversary to execute arbitrary operating-system commands.
Please contact the product support for further details at the below mentioned email addresses:
PAM360: pam360-support@manageengine.com
Password Manager Pro: passwordmanagerpro-support@manageengine.com