CVE-2026-75791
Received Received - Intake

Authentication Bypass in ManageEngine ADSelfService Plus

Vulnerability report for CVE-2026-75791, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: ManageEngine

Description

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zohocorp manageengine_adselfservice_plus to 7001 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-75791 is an authentication bypass vulnerability in Zohocorp ManageEngine ADSelfService Plus versions before build 7001. It allows unauthenticated remote attackers to bypass authorization checks in the REST API and access restricted operations.

Detection Guidance

To detect this vulnerability, check the version of ADSelfService Plus installed on your system. If the version is 7000 or below, the system is vulnerable. Compare the build number against the fixed version 7001 or later.

Impact Analysis

This vulnerability could allow attackers to read sensitive configuration details or modify administrator-restricted settings. This may disrupt legitimate access to the product and potentially lead to unauthorized changes in the system.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access to sensitive directory configuration details or administrator-restricted settings. Unauthorized modifications or access to such data may violate data protection requirements under these regulations, depending on the data involved.

Mitigation Strategies

Immediately update ADSelfService Plus to build 7001 or later to enforce authorization checks. Ensure no unauthorized changes have been made to configurations or settings before and after the update.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75791. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart