{"id":"CVE-2026-75791","published":"2026-09-22T13:17:11.170","lastModified":"2026-09-22T19:32:25.730","description":"Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.","cvssScore":8.6,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","cwes":["CWE-306"],"vendors":[],"products":[],"references":[{"url":"https://www.manageengine.com/products/self-service-password/advisory/CVE-2026-75791.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows attackers to bypass authentication in the REST API of Zohocorp ManageEngine ADSelfService Plus versions before build 7001, enabling unauthorized access to sensitive features.","exploitability":"Exploitation is relatively straightforward as it requires access to the REST API, which may be exposed to the internet or internal network.","blast_radius":"If exploited, this vulnerability could lead to unauthorized access to critical system functions, potentially allowing full control over the affected system.","remediation":"Upgrade to build 7001 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","api","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:28:33.089Z"}}