CVE-2026-18912: SQL Injection
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ManageEngine DataSecurity Plusto a version that resolves this vulnerability.Fixed in 6310
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated technician can exploit the vulnerability through the Reports module. The available information does not indicate that unauthenticated users can exploit it.
Which deployments are affected?
ManageEngine DataSecurity Plus versions before 6310 are affected. Version 6310 and later are not identified as vulnerable by the provided advisory information.
What access and impact does exploitation involve?
An attacker needs technician authentication and can execute arbitrary SQL queries through the Reports module. The stated impact includes exposure of confidential information; integrity and availability impacts are not listed.