CVE-2026-18911: Input Validation
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ManageEngine DataSecurity Plusto a version that resolves this vulnerability.Fixed in 6310 - Compensating control
Restrict network access to DataSecurity Plus so that unenrolled/unauthorized agents cannot reach it directly; only allow required, authenticated agent traffic paths until the upgrade to 6310 is completed.
Event History
Frequently Asked Questions
Which deployments are affected?
ManageEngine DataSecurity Plus versions before 6310 are affected.
What does an attacker need to exploit this issue?
An unenrolled agent must be able to send requests to the affected DataSecurity Plus deployment. The vulnerability does not require prior privileges or user interaction, but exploitation has high attack complexity.
What is the recommended remediation?
Upgrade ManageEngine DataSecurity Plus to version 6310 or later.