Authentication Bypass in ManageEngine ADSelfService Plus by Zohocorp
CVE-2026-75791

8.6HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
22 September 2026

What is CVE-2026-75791?

The authentication bypass vulnerability in ManageEngine ADSelfService Plus enables unauthorized access to the REST API. Versions prior to build 7001 are susceptible, allowing potential exploiters to bypass authentication mechanisms, compromising user security and sensitive data.

Affected Version(s)

ManageEngine ADSelfService Plus 0 < 7001

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.