Executive brief
ManageEngine Endpoint Central, a tool used by IT departments to manage and secure corporate devices, contains a flaw in how it handles email server settings. Under specific conditions, an administrative user could view sensitive mail configuration data created by other administrators because the information is transmitted or stored insecurely. This could lead to the exposure of service credentials or internal mail server details to unauthorized staff members.
Technical details
A vulnerability classified as CWE-319 (Cleartext Transmission of Sensitive Information) exists in ManageEngine Endpoint Central. When basic authentication is configured for external mail service integrations, administrative users may be able to access configuration data created by other administrators that should otherwise be restricted. The issue stems from the insecure handling of sensitive mail service information during transmission or within the administrative interface. Exploitation requires network access and at least low-level administrative privileges. The vendor has released patches in versions 11.4.2528.34 and 11.5.2600.13 to address this behavior.
Affected products
- Zohocorp ManageEngine Endpoint Central before 11.4.2528.34; before 11.5.2600.13
Timeline
- 2026-01-23: patched: Fixed builds released.
- 2026-07-21: disclosed: CVE published.