← Back to search

CVE-2026-75791

8.6 HIGH

Published 2026-09-22 · Updated 2026-09-22

AI risk analysis

Summary
This vulnerability allows attackers to bypass authentication in the REST API of Zohocorp ManageEngine ADSelfService Plus versions before build 7001, enabling unauthorized access to sensitive features.
Exploitability
Exploitation is relatively straightforward as it requires access to the REST API, which may be exposed to the internet or internal network.
Blast radius
If exploited, this vulnerability could lead to unauthorized access to critical system functions, potentially allowing full control over the affected system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to build 7001 or later.
auth-bypassapiweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Weaknesses

CWE-306

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.