CVE
CVE-2026-12263
0field notes · 1digest CVSS 8.8
The verdict
An attacker can bypass authentication entirely in ManageEngine Password Manager Pro and PAM360 by exploiting broken SAML validation. No credentials needed. Given that these products literally store every privileged credential in your environment, a bypass here is about as bad as it gets.
Patch urgency · Patch immediately
Daily digests