CVE-2026-75791

8.6

Zohocorp · ManageEngine ADSelfService Plus

ManageEngine ADSelfService Plus contains an authentication bypass vulnerability within its REST API, allowing unauthenticated remote attackers to potentially compromise system integrity and availability.

Executive summary

An unauthenticated remote attacker can exploit a flaw in the ManageEngine ADSelfService Plus REST API to bypass security controls, posing a significant risk to organizational identity infrastructure.

Vulnerability

The application fails to perform necessary authentication checks for critical functions within the REST API, allowing an unauthenticated attacker to interact with the service without valid credentials.

Business impact

Successful exploitation of this vulnerability permits unauthorized access to sensitive identity management functions. Given the CVSS score of 8.6, this flaw carries a high risk of system compromise, potentially leading to unauthorized password resets, account takeovers, or denial of service, which could disrupt critical business authentication workflows.

Remediation

Immediate Action: Upgrade Zohocorp ManageEngine ADSelfService Plus to build 7001 or later to resolve the authentication bypass vulnerability.

Proactive Monitoring: Monitor API access logs for anomalous, unauthenticated requests or patterns indicating unauthorized attempts to trigger administrative functions.

Compensating Controls: Implement strict network access control lists (ACLs) to limit access to the ADSelfService Plus REST API to known, trusted management segments until the patch can be applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a critical security risk due to the potential for unauthenticated access to identity infrastructure. Administrators should prioritize the deployment of build 7001 immediately across all production environments to mitigate the risk of unauthorized access and potential system takeover.

More Zohocorp CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources