Junglewise Threat Intelligence

CVE-2026-18911: ManageEngine DataSecurity Plus agent authentication bypass

CVE-2026-18911 · Severity: high · CVSS 7.5 · Published 2026-09-18

Executive brief

ManageEngine DataSecurity Plus is a data auditing and security platform used to monitor file access, detect ransomware, and enforce compliance regulations. The vulnerability allows unenrolled agents to send requests to the service without proper credential validation, potentially enabling attackers to retrieve agent configuration data and access service account credentials used for auditing domain and file-share activity.

Technical details

An authentication bypass vulnerability in the agent communication mechanism allows requests from configured yet unenrolled agents to be processed without credential validation. The vulnerability stems from insufficient validation of agent credentials, allowing attackers to bypass authentication checks. A remote attacker can exploit this by sending requests as an unenrolled agent to retrieve the agent's identity and configuration data, and potentially escalate to access service account credentials configured for domain or file-share auditing. The vulnerability affects versions 6300 and earlier; the fix enforces credential validation for all agent requests and rejects blank or invalid credentials. A patch was released on August 6, 2026 in version 6310.

Affected products

  • ManageEngine DataSecurity Plus 6300 and earlier

Timeline

  • 2026-09-18: disclosed
  • 2026-08-06: patched: Version 6310 released

References