CVE-2026-74849

9.8

Zohocorp · ManageEngine ADSelfService Plus

ManageEngine ADSelfService Plus is vulnerable to OS command injection in the GINA client, allowing unauthenticated remote code execution.

Executive summary

A critical remote code execution vulnerability in Zohocorp ManageEngine ADSelfService Plus allows unauthenticated attackers to gain full system control.

Vulnerability

This is an OS command injection flaw (CWE-78) located within the GINA client component. The vulnerability is exploitable by an unauthenticated attacker over the network with no user interaction required.

Business impact

The potential for unauthenticated remote code execution poses a severe risk to organizational infrastructure, as it grants attackers the ability to execute arbitrary commands with the privileges of the application. Given the CVSS score of 9.8, this vulnerability could lead to total system compromise, exfiltration of sensitive identity data, and the potential for lateral movement within the network. Such an incident would likely result in significant operational disruption and a breach of security compliance standards.

Remediation

Immediate Action: Administrators must update Zohocorp ManageEngine ADSelfService Plus to build 7001 or later immediately.

Proactive Monitoring: Review web server and system logs for unusual process execution or shell commands originating from the GINA client service.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common OS command injection patterns targeting the application.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability cannot be overstated, as it represents a direct threat to the integrity and availability of the ManageEngine environment. Organizations must prioritize the transition to version 7001 to eliminate this attack vector. Failure to patch will leave the system open to potential remote exploitation, necessitating swift action from all security and IT operations teams.

More Zohocorp CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources