CVE-2026-1367

8.3

Zohocorp · ManageEngine ADSelfService Plus

ManageEngine ADSelfService Plus is vulnerable to an authenticated SQL injection flaw in the search report option, allowing potential database manipulation by authenticated users.

Executive summary

A high severity SQL injection vulnerability in Zohocorp ManageEngine ADSelfService Plus, affecting versions 6522 and below, poses a significant risk of unauthorized data access and manipulation.

Vulnerability

This vulnerability is a SQL injection flaw (CWE-89) within the search report functionality. It requires the attacker to possess authenticated access to the application to trigger the malicious SQL commands.

Business impact

Successful exploitation allows an attacker to execute arbitrary SQL queries against the underlying database, potentially leading to the theft of sensitive identity data or unauthorized modification of system records. With a CVSS score of 8.3, this flaw is categorized as High severity, reflecting the critical nature of the compromised information typically managed by ADSelfService Plus.

Remediation

Immediate Action: Update Zohocorp ManageEngine ADSelfService Plus to build 6523 or later as specified in the official vendor advisory.

Proactive Monitoring: Review application and database logs for anomalous query patterns or unauthorized access attempts originating from authenticated service accounts.

Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns until the patch can be applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the sensitive nature of the data stored within ADSelfService Plus, organizations should prioritize patching this vulnerability immediately. Administrators must ensure that all instances are updated to version 6523 or higher to prevent potential exploitation by malicious actors who may gain access to low-privilege user credentials.

More Zohocorp CVEs

Sources

Originally found and disclosed by Nguyen Dang Toan, per the CVE Program record.