CVE-2026-27655
7.3Zohocorp · ManageEngine Exchange Reporter Plus
ManageEngine Exchange Reporter Plus is vulnerable to Stored Cross-Site Scripting (XSS) via the Permissions Based on Mailboxes report, allowing for potential malicious script injection.
Executive summary
A Stored Cross-Site Scripting vulnerability in Zohocorp ManageEngine Exchange Reporter Plus allows authenticated users to inject malicious scripts, potentially leading to unauthorized actions.
Vulnerability
This is a Stored Cross-Site Scripting (CWE-79) vulnerability located within the Permissions Based on Mailboxes report. The attack requires the attacker to be an authenticated user with low privileges to successfully inject malicious scripts into the application.
Business impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the context of an administrator or other user session. This may result in the theft of session cookies, unauthorized access to sensitive mailbox permissions data, or the performance of unauthorized actions on behalf of the victim. Given the CVSS score of 7.3, this is categorized as a High severity issue that poses a significant risk to the integrity and confidentiality of the reporting interface.
Remediation
Immediate Action: Upgrade Zohocorp ManageEngine Exchange Reporter Plus to build 5802 or later to address the vulnerability.
Proactive Monitoring: Review application access logs for unusual activity or suspicious script patterns originating from the Permissions Based on Mailboxes report module.
Compensating Controls: Implement a Web Application Firewall (WAF) to filter and block malicious payloads associated with XSS attacks until the patch can be applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Security teams should prioritize updating the ManageEngine Exchange Reporter Plus instance to version 5802 or later. Given the nature of Stored XSS, failing to patch could allow for persistent threats within the administrative interface. Please verify the update against the official Zohocorp security advisory to ensure complete remediation of the affected component.