CVE-2026-12263
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass
CVSS
8.8
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 13, 2026 · Last modified: Aug 13, 2026 · CWE-347
Not enough EPSS history yet.
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-487912.0 LOW—
——0sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certificate. Version 2.1.0 re-added this verification with enhancements that adhere to the Sigstore verification spec. The old sigstore-conformance test for this check was built incorrectly. This vulnerability impacts only users verifying bundles with `dev.sigstore:sigstore-java:2.0.0`. Older versions are not affected; it is fixed in `dev.sigstore:sigstore-java:2.1.0` A malicious actor may exploit this if they were able to access a users system and exfiltrate the temporary private key used during signing and then reuse an old fulcio certificate later without requiring direct access to the user's credentials. Users may protect themselves by re-verifying their artifacts using the newest sigstore-java or another current sigstore client. Transparency logs may also be audited for unauthorized signatures for a suspected reused identity.13hCVE-2026-687597.2 HIG—
——0A holder of a valid integration credential may impersonate other users under specific conditions.18hCVE-2026-687577.5 HIG—
——0A user with access to a valid SAML response may impersonate another user under specific conditions.17hCVE-2026-627575.3 MED16.2%
——5Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.22hCVE-2026-155568.1 HIG11.5%
——3A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.21hCVE-2026-105799.8 CRI22.8%
——7A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.2d