← Vulnerability feed

Vulnerability record · CVE-2026-3324 · published 16 April 2026

CVE-2026-3324: Zohocorp manageengine log360 authentication bypass via alternate path vulnerability

Zohocorp · Manageengine Log360

Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.

8.2 CVSS 3.1 High EPSS 2.1% · top 19.4% CWE-288 · Authentication bypass via alternate path
8.2CVSS 3.1 base score
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
11 Aug 2026Last modified by NVD

Description

Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-3324 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-20136Zohocorp manageengine log360 missing authentication for critical function vulnerabilityManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthentica…EPSS 11%9.8CVE-2021-40175Zohocorp manageengine log360 unrestricted file upload vulnerabilityZoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.EPSS 7.0%9.8CVE-2021-40177Zohocorp manageengine log360 vulnerabilityZoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.EPSS 4.6%9.8CVE-2020-24786Zohocorp manageengine adselfservice plus improper authentication vulnerabilityAn issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus befo…EPSS 13%8.8CVE-2021-40172Zohocorp manageengine log360 cross-site request forgery vulnerabilityZoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.EPSS 0.99%8.8CVE-2021-40174Zohocorp manageengine log360 cross-site request forgery vulnerabilityZoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.EPSS 0.99%8.1CVE-2023-35785Zohocorp manageengine ad360 improper authentication vulnerabilityZoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and b…EPSS 2.4%6.1CVE-2021-40176Zohocorp manageengine log360 cross-site scripting vulnerabilityZoho ManageEngine Log360 before Build 5225 allows stored XSS.EPSS 0.82%

Source: NIST National Vulnerability Database (record CVE-2026-3324), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.