External risk intelligence

ManageEngine Applications Manager Installer Exposes Google Cloud Service Account Key

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-86708

The vulnerability exists within the application installer. Installer files and artifacts are typically used during build-time or deployment and are not intended to be exposed to the public internet or remain reachable after the product is installed and configured in a production environment.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in ZohoCorp ManageEngine Applications Manager that could expose a Google Cloud service account's private key. If exploited, an unauthenticated attacker could impersonate the service account, potentially gaining unauthorized access to or the ability to modify sensitive cloud resources.

  • Installer key exposure allows cloud account impersonation.
  • Critical access risk if Google Cloud service account is exposed.
  • Verify if installer files are exposed or still accessible.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by accessing the ManageEngine Applications Manager installer, which exposes a Google Cloud service account private key. This exposure allows the attacker to impersonate the service account, potentially leading to unauthorized access or modification of associated cloud resources.

  • Attacker gains access to installer.
  • Private key exposure is triggered.
  • Unauthorized cloud resource access.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could potentially impersonate a service account, leading to unauthorized access or modification of associated Google Cloud resources. This could occur when the Applications Manager installer, which may contain a Google Cloud service-account private key, is accessible.

  • Google Cloud service account credentials.
  • Installer exposure could lead to key access.
  • Unauthorized access or modification of cloud resources.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts ZohoCorp ManageEngine Applications Manager, suggesting that application owners and infrastructure teams are primarily responsible for remediation. The immediate first step is to identify all instances of the affected software, determine their reachability and business criticality, and then engage the accountable owner to plan a risk-based remediation strategy.

  • Application and infrastructure teams own this.
  • Verify installer reachability and installed instances.
  • Coordinate vendor updates and risk mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ZohoCorp ManageEngine Applications Manager?

ManageEngine Applications Manager is a monitoring solution used by IT teams to oversee the health and performance of servers, databases, and cloud infrastructure. It acts as a centralized dashboard to track application availability and resource usage, which often requires integration with cloud services like Google Cloud to gather telemetry and manage monitored assets.

What does CWE-321 mean for CVE-2026-86708?

CWE-321 refers to the use of hard-coded cryptographic keys. In this case, the Applications Manager installer included a Google Cloud service account private key directly in its files. This is a vulnerability because software should never store sensitive credentials in a static, pre-configured way, as these keys are easily extracted if the installer file is accessed by an unauthorized person.

How is this vulnerability triggered?

The flaw is triggered when someone gains access to the specific installer files provided for ManageEngine Applications Manager versions 182200 and below. It is important to note that simply running the installed application does not inherently trigger this; the risk specifically arises from exposure of the installer package itself, which contains the embedded, unprotected private key.

Is this CVE relevant if my server is internal?

According to Halo Surface Signal, this vulnerability is very unlikely to be reachable if your systems are properly managed. Because the risk is tied to the installer files—which are typically used only during setup—they should not be accessible on the public internet. You should care most if these installer files were inadvertently placed on a web-accessible server or a shared, public-facing repository.

What should I do if I run this software?

Your priority is to ensure that no installer packages for ManageEngine Applications Manager are left on accessible file shares, web servers, or publicly reachable storage. Verify that you are running a supported, secure version of the software by checking official vendor updates. If you suspect an installer file may have been exposed, assume the embedded service account key is compromised and rotate it immediately within your Google Cloud environment.

References