CVE-2026-4108
7.3Zohocorp · ManageEngine Exchange Reporter Plus
ManageEngine Exchange Reporter Plus contains a stored cross-site scripting (XSS) vulnerability in the Non-Owner Mailbox Permission report, allowing authenticated users to execute malicious scripts.
Executive summary
A stored cross-site scripting vulnerability in ManageEngine Exchange Reporter Plus enables authenticated attackers to execute arbitrary scripts within the context of a victim session.
Vulnerability
This vulnerability is a stored cross-site scripting (CWE-79) flaw located within the Non-Owner Mailbox Permission report. It requires an authenticated user with low-level privileges to inject malicious scripts that execute when a victim views the affected report.
Business impact
The ability for an attacker to execute arbitrary scripts in the context of an administrator or other user session poses a significant risk to data confidentiality and integrity. Successful exploitation could lead to session hijacking, unauthorized access to sensitive mailbox reports, or the modification of application data. With a CVSS score of 7.3, this flaw is categorized as High severity due to the potential for impacting administrative sessions.
Remediation
Immediate Action: Upgrade to version 5802 or later of ManageEngine Exchange Reporter Plus to apply the vendor-provided patch.
Proactive Monitoring: Review application access logs for suspicious input patterns within the Non-Owner Mailbox Permission report and monitor for unusual script execution activity in user sessions.
Compensating Controls: Deploy a Web Application Firewall (WAF) with robust XSS protection rules to inspect and sanitize incoming traffic to the application until the update is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the High severity of this vulnerability, organizations should prioritize updating their ManageEngine Exchange Reporter Plus instances to version 5802 immediately. While the requirement for authentication reduces the immediate threat surface, the potential for privilege escalation and session compromise necessitates prompt remediation to maintain a secure environment.