CVE-2026-75791: Authentication bypass vulnerability
Published Sep 22, 2026
·Updated
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.
Affected Software
1 affected component
Zohocorp ManageEngine ADSelfService Plus<7001
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zohocorp ManageEngine ADSelfService Plusto a version that resolves this vulnerability.Fixed in 7001
Event History
Sep 22, 2026
CVE Published
via MITRE·12:03 PM
Data Sourced
via MITRE·12:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Zohocorp ManageEngine ADSelfService Plus deployments running builds before 7001 are affected. The issue is in the product's REST API.
2
Does exploitation require an authenticated account or user interaction?
No. The supplied CVSS vector indicates network-based exploitation with no privileges required and no user interaction.
3
What is the potential impact of successful exploitation?
The supplied severity data indicates low confidentiality and integrity impact, and high availability impact.