Junglewise Threat Intelligence

CVE-2026-75791: Zoho ManageEngine ADSelfService Plus authentication bypass in REST API

CVE-2026-75791 · Severity: high · CVSS 8.6 · Published 2026-09-22

Vendors: Zoho.

Executive brief

ADSelfService Plus is a password management and identity access control tool that manages Active Directory user authentication and authorization. An authentication bypass vulnerability in its REST API allows unauthenticated attackers to access sensitive configuration information and modify administrator settings, potentially disrupting legitimate user access or escalating privileges.

Technical details

The vulnerability is an authentication bypass in the REST API that allows specially crafted requests to reach restricted API operations without proper authorization checks. An unauthenticated remote attacker can exploit this to read product and directory configuration and modify administrator-restricted settings. The issue was patched in build 7001 by enforcing consistent authorization checks across the REST API.

Affected products

  • Zoho ManageEngine ADSelfService Plus build 7000 and below

Timeline

  • 2026-09-22: disclosed
  • 2026-08-24: patched: Fixed in build 7001

References

Related threats