Description
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.
Published: 2026-09-18
Score: 7.5 High
EPSS: 1.1% Low
KEV: No
Impact: Authentication bypass allowing unauthorized agent requests
Action: Immediate Patch
AI Analysis

Impact

ManageEngine DataSecurity Plus versions earlier than 6310 contain a flaw that lets agents that have not been properly enrolled send requests without authenticating. This bypass allows attackers to perform actions through the DataSecurity Plus interface that they would normally be denied, potentially leading to unauthorized data access or manipulation. The weakness is a form of improper input validation (CWE‑20).

Affected Systems

The vulnerability affects Zohocorp’s ManageEngine DataSecurity Plus software. All deployments running versions prior to 6310 are impacted. The advisory lists these products under the vendor product name Zohocorp:ManageEngine DataSecurity Plus.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity. The EPSS score of 1% suggests that the probability of exploitation in the wild is low but not negligible. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers with network reach to the DataSecurity Plus server can exploit the flaw by tricking an unsupported or non‑enrolled agent into sending crafted requests, thereby bypassing authentication. Based on the description, it is inferred that the attack vector is remote over the network, exploiting the agent communication channel.

Generated by OpenCVE AI on September 19, 2026 at 20:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ManageEngine DataSecurity Plus to version 6310 or newer to eliminate the authentication bypass flaw.
  • Configure the system to reject requests from any agent that is not officially enrolled and ensure that enrollment checks are enforced for all incoming agent traffic.
  • Limit network access to the DataSecurity Plus server using firewall rules and monitor for suspicious agent activity to detect potential bypass attempts.

Generated by OpenCVE AI on September 19, 2026 at 20:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Agent Authentication Bypass in ManageEngine DataSecurity Plus Enabling Unauthenticated Requests

Sat, 19 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Title Agent Authentication Bypass in ManageEngine DataSecurity Plus Enabling Unauthenticated Requests

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.
First Time appeared Zohocorp
Zohocorp manageengine Datasecurity Plus
Weaknesses CWE-20
CPEs cpe:2.3:a:zohocorp:manageengine_datasecurity_plus:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Datasecurity Plus
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Zohocorp Manageengine Datasecurity Plus
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-18T19:38:21.135Z

Reserved: 2026-08-05T06:00:14.679Z

Link: CVE-2026-18911

cve-icon Vulnrichment

Updated: 2026-09-18T19:38:17.186Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T06:16:31.727

Modified: 2026-09-18T20:17:11.233

Link: CVE-2026-18911

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:45:17Z

Weaknesses
  • CWE-20

    Improper Input Validation