Authenticated Remote Code Execution Vulnerability in ManageEngine by Zohocorp
CVE-2026-2740

8.4HIGH

What is CVE-2026-2740?

ManageEngine products from Zohocorp, including ADSelfService Plus, DataSecurity Plus, and RecoveryManager Plus, have a significant vulnerability that allows authenticated remote code execution. This issue arises from a flaw in a third-party dependency, potentially giving attackers the ability to execute arbitrary code on agent machines if they have authenticated access. Organizations using affected versions are advised to apply the necessary updates to mitigate this security risk.

Affected Version(s)

ManageEngine ADSelfService Plus 0 < 6525

ManageEngine DataSecurity Plus 0 < 6264

ManageEngine RecoveryManager Plus 0 < 6313

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.