Description
Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in ManageEngine ADSelfService Plus permits bypass of the multi‑factor authentication mechanism, allowing an attacker to obtain authenticated sessions without the second factor. This weakness, identified as CWE‑290, undermines confidentiality and integrity by granting unintended access to protected resources and potentially enabling privilege escalation. The impact is that unauthorized users can act with the same privileges as legitimate users, exposing sensitive data and services.

Affected Systems

Zohocorp ManageEngine ADSelfService Plus versions prior to 6524 are affected. All installations running any earlier build should upgrade to a supported release. No additional vendor or product information is provided in the advisory.

Risk and Exploitability

The CVSS score of 7.1 marks the issue as high severity, while the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The advisory does not specify the attack vector; however, it is inferred that an attacker who can trigger or manipulate authentication requests—either remotely or from within the network—may bypass MFA, potentially accessing user accounts and sensitive data.

Generated by OpenCVE AI on July 30, 2026 at 18:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ManageEngine ADSelfService Plus to version 6524 or later to apply the official fix.
  • Verify that multi‑factor authentication is correctly configured and enforced for all authentication flows.
  • Enable and review logging of authentication attempts to detect potential bypass attempts.

Generated by OpenCVE AI on July 30, 2026 at 18:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
Title Multi Factor Auth Bypass
First Time appeared Zohocorp
Zohocorp manageengine Adselfservice Plus
Weaknesses CWE-290
CPEs cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Adselfservice Plus
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Zohocorp Manageengine Adselfservice Plus
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-07-21T12:18:37.554Z

Reserved: 2026-02-25T07:08:40.731Z

Link: CVE-2026-3183

cve-icon Vulnrichment

Updated: 2026-07-21T12:18:33.752Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T18:15:13Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing