Executive brief
ManageEngine ADSelfService Plus, a tool used by employees to reset their own passwords and manage their accounts, contains a security flaw that allows attackers to bypass multi-factor authentication (MFA). If an attacker already knows a user's standard password, they can exploit this vulnerability to skip the secondary security check and gain full access to the user's account. This could lead to unauthorized access to sensitive corporate resources and potential account takeover.
Technical details
A broken authentication vulnerability exists in ManageEngine ADSelfService Plus (builds 6523 and earlier) due to incomplete enforcement of session-level authentication state checks at sensitive API endpoints. An attacker who has already obtained a valid user's domain password can exploit this flaw to bypass MFA requirements. By interacting with the vulnerable API, the attacker can transition to an authenticated state without completing the required secondary authentication factors. This allows for unauthorized account access and privilege escalation within the application. The issue is resolved in build 6524 by ensuring privileged operations require a session that has successfully completed MFA.
Affected products
- Zohocorp ManageEngine ADSelfService Plus Builds 6523 and earlier
Timeline
- 2026-01-31: patched: Fixed in build 6524
- 2026-07-21: disclosed: NVD publication date