Junglewise Threat Intelligence

CVE-2026-3879: Zohocorp ManageEngine Exchange Reporter Plus Stored XSS in Equipment Mailbox Details report

CVE-2026-3879 · Severity: high · CVSS 7.3 · Published 2026-04-03

Technologies: Zohocorp Manageengine Exchange Reporter Plus, Zoho Corporation Exchange Reporter Plus. Vendors: Zohocorp, Zoho Corporation.

Executive brief

ManageEngine Exchange Reporter Plus, a reporting and auditing solution for Microsoft Exchange environments, is vulnerable to a security flaw in its Equipment Mailbox Details report. An attacker with administrative access to the Exchange organization can inject malicious scripts into the reporting interface. If another user views the compromised report, the attacker could potentially take over their session or perform unauthorized actions within the application.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Equipment Mailbox Details report within the Reports module of ManageEngine Exchange Reporter Plus. The flaw is caused by improper input validation of data retrieved from the Exchange environment. An authenticated attacker with Exchange administrative privileges can inject malicious scripts that are stored and later executed in the browser of any user who views the affected report. This could lead to session hijacking or unauthorized administrative actions within the Exchange Reporter Plus console. The issue is resolved in version 5802.

Affected products

  • Zohocorp ManageEngine Exchange Reporter Plus Builds 5801 and below

Timeline

  • 2026-03-19: patched: Fixed in version 5802
  • 2026-04-03: disclosed: Initial advisory publication

References

Related threats