Executive brief
Multiple ManageEngine products used for password management, data security, and backup are vulnerable to a security flaw that allows an attacker to take control of employee computers. An authorized user on the corporate network could exploit this vulnerability to run malicious commands on any machine where the product's agent software is installed. This could lead to full system compromise, data theft, or the spread of ransomware across the organization.
Technical details
An authenticated remote code execution (RCE) vulnerability exists in ManageEngine ADSelfService Plus (before 6525), DataSecurity Plus (before 6264), and RecoveryManager Plus (before 6313). The flaw is classified as a command injection (CWE-77) resulting from improper access controls in the service communication channel used to deploy and manage product agents (Login Agent, Backup Agent, and DataSecurity Agent). An attacker with low-privileged domain credentials can exploit this by accessing the communication channel between the server and client to execute arbitrary commands on the agent machines. The vulnerability is rooted in a third-party dependency. Patches are available via the respective product upgrade packs.
Affected products
- Zoho ManageEngine ADSelfService Plus before 6525
- Zoho ManageEngine DataSecurity Plus before 6264
- Zoho ManageEngine RecoveryManager Plus before 6313
Timeline
- 2026-02-05: patched: ADSelfService Plus fixed in Build 6525
- 2026-02-13: patched: DataSecurity Plus fixed in Build 6264
- 2026-03-24: patched: RecoveryManager Plus fixed in Build 6313
- 2026-05-21: advisory: NVD and Vendor advisory published