Junglewise Threat Intelligence

CVE-2026-27655: Zohocorp ManageEngine Exchange Reporter Plus stored XSS in mailbox reports

CVE-2026-27655 · Severity: high · CVSS 7.3 · Published 2026-04-03

Technologies: Zohocorp Manageengine Exchange Reporter Plus, Zoho Corporation Exchange Reporter Plus. Vendors: Zohocorp, Zoho Corporation.

Executive brief

ManageEngine Exchange Reporter Plus, a tool used for monitoring and reporting on Microsoft Exchange environments, is vulnerable to a security flaw in its mailbox permissions reporting module. An attacker with existing administrative access to the Exchange environment could inject malicious scripts that execute when other users view specific reports. This could allow the attacker to hijack user sessions or perform unauthorized actions within the reporting software.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in ManageEngine Exchange Reporter Plus builds 5801 and below. The flaw is located within the 'Permissions Based on Mailboxes' report in the Reports module due to improper input validation. An authenticated attacker with Exchange administrative privileges can inject malicious scripts into mailbox metadata that the application later renders without sufficient sanitization. When a victim views the affected report, the script executes in their browser context, potentially allowing the attacker to perform actions with the victim's privileges. The issue is resolved in version 5802.

Affected products

  • Zohocorp ManageEngine Exchange Reporter Plus Builds 5801 and below

Timeline

  • 2026-03-19: patched: Fixed in version 5802
  • 2026-04-03: advisory: Initial NVD publication and vendor advisory release

References

Related threats