Description
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Zohocorp ManageEngine Endpoint Central allows the transmission of sensitive data in cleartext for all affected versions, potentially exposing confidential information to anyone who can observe network traffic. This flaw is classified under CWE‑319 and results in a confidentiality breach, with no stated impact on integrity or availability.

Affected Systems

Zohocorp ManageEngine Endpoint Central, all releases prior to 11.4.2528.34.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate risk, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network‑based; an adversary monitoring traffic between a client and the Endpoint Central server could capture the transmitted data. No privileged access is required, and the primary consequence is the loss of confidentiality.

Generated by OpenCVE AI on July 30, 2026 at 18:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 11.4.2528.34 or newer to eliminate the cleartext transmission flaw.
  • If an upgrade cannot be performed immediately, enforce TLS/SSL for all communications between Endpoint Central clients and the server to encrypt transmitted data in transit.
  • Restrict the Endpoint Central server’s network exposure by limiting access to trusted hosts or a dedicated management network, and consider deploying VPNs to further reduce interception risk.

Generated by OpenCVE AI on July 30, 2026 at 18:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Description Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.
Title Sensitive Data Exposure
First Time appeared Zohocorp
Zohocorp manageengine Endpoint Central
Weaknesses CWE-319
CPEs cpe:2.3:a:zohocorp:manageengine_endpoint_central:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Endpoint Central
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Zohocorp Manageengine Endpoint Central
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-07-21T15:03:24.772Z

Reserved: 2026-02-25T07:08:29.976Z

Link: CVE-2026-3182

cve-icon Vulnrichment

Updated: 2026-07-21T15:03:21.503Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T18:15:13Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information