ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.Referenceshttps://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2026-86678.html