Description
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
Published: 2026-09-18
Score: 7.7 High
EPSS: 1.5% Low
KEV: No
Impact: Arbitrary SQL Execution
Action: Immediate Patch
AI Analysis

Impact

ManageEngine DataSecurity Plus versions earlier than 6310 contain an authenticated SQL injection flaw in the Reports module. An attacker who can authenticate as a technician can inject and execute arbitrary SQL statements against the underlying database, potentially retrieving sensitive data, modifying records, or executing database commands that may lead to further compromise. This weakness is a classic example of CWE‑89.

Affected Systems

The vulnerable scope is the ManageEngine DataSecurity Plus product from Zohocorp, specifically all releases prior to 6310 regardless of installation platform. Any deployment that uses the Reports module and accepts technician‑level credentials is affected.

Risk and Exploitability

The CVSS score of 7.7 indicates a high risk potential, and the EPSS score of 1.5% indicates exploitation is plausible but not extremely common. Because the attack requires authenticated access, the vulnerability is not exploitable by unauthenticated users, and it is not listed in CISA’s KEV catalog. The overall threat level remains high for environments where technician credentials are accessible or have not been properly secured.

Generated by OpenCVE AI on September 19, 2026 at 19:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ManageEngine DataSecurity Plus to version 6310 or later as indicated by the vendor advisory.
  • If an upgrade cannot be performed immediately, restrict or disable the Reports module for accounts that do not require it to block the injection vector.
  • Implement strict role‑based access controls, regularly rotate technician credentials, and monitor database logs for abnormal query activity.

Generated by OpenCVE AI on September 19, 2026 at 19:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Authenticated SQL Injection in ManageEngine DataSecurity Plus Reports Module

Fri, 18 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
First Time appeared Zohocorp
Zohocorp manageengine Datasecurity Plus
Weaknesses CWE-89
CPEs cpe:2.3:a:zohocorp:manageengine_datasecurity_plus:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Datasecurity Plus
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Zohocorp Manageengine Datasecurity Plus
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-18T14:31:47.807Z

Reserved: 2026-08-05T06:00:56.324Z

Link: CVE-2026-18912

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:49.315Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T06:16:33.250

Modified: 2026-09-18T15:17:06.643

Link: CVE-2026-18912

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:00:14Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')