Junglewise Threat Intelligence

CVE-2026-4108: Zohocorp ManageEngine Exchange Reporter Plus Stored XSS in Reports

CVE-2026-4108 · Severity: high · CVSS 7.3 · Published 2026-04-03

Technologies: Zohocorp Manageengine Exchange Reporter Plus, Zoho Corporation Exchange Reporter Plus. Vendors: Zohocorp, Zoho Corporation.

Executive brief

ManageEngine Exchange Reporter Plus is a reporting and auditing tool for Microsoft Exchange environments. A security vulnerability in the 'Non-Owner Mailbox Permission' report allows an attacker to inject malicious scripts into the system. If an administrator views the affected report, the attacker could potentially take over their session, leading to unauthorized access to sensitive email reporting data or configuration changes.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in ManageEngine Exchange Reporter Plus builds 5801 and below within the 'Non-Owner Mailbox Permission' report module. The root cause is improper neutralization of input during web page generation (CWE-79). An authenticated attacker with low-level privileges can inject malicious scripts that are stored on the server. When a victim (typically an administrator) views the compromised report, the script executes in their browser context. This can lead to session hijacking or unauthorized actions performed on behalf of the victim. The issue is resolved in build 5802 through improved input validation.

Affected products

  • Zohocorp ManageEngine Exchange Reporter Plus Builds 5801 and below

Timeline

  • 2026-03-19: patched: Fixed in version 5802
  • 2026-04-03: advisory: Initial advisory published by vendor and NVD

References

Related threats