CVE-2026-74849: Remote code execution vulnerability
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zohocorp ManageEngine ADSelfService Plusto a version that resolves this vulnerability.Fixed in 7001
Event History
Frequently Asked Questions
Which deployments are affected?
Zohocorp ManageEngine ADSelfService Plus deployments running a version before build 7001 are affected. The vulnerability is in the GINA client.
Does exploitation require authentication or user interaction?
No. The reported vector is network-accessible, with low attack complexity, no privileges required, and no user interaction required.
What could a successful attacker do?
Successful exploitation can result in remote code execution through OS command injection. The reported impact includes high confidentiality, integrity, and availability impact.