CVE-2015-7765

ZOHO ManageEngine OpManager <11.5.11600 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2015-7765. PoCs published by Metasploit, including Metasploit module exploits/windows/http/manage_engine_opmanager_rce.

AI-analyzed exploit summary This Metasploit module exploits a default credential vulnerability in ManageEngine OpManager, using a hidden account 'IntegrationUser' with a default password 'plugin' to execute arbitrary SQL queries, write a WAR payload to disk, and trigger its deployment for remote code execution.

Description

ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotejava
https://www.exploit-db.com/exploits/38221

This Metasploit module exploits a default credential vulnerability in ManageEngine OpManager, using a hidden account 'IntegrationUser' with a default password 'plugin' to execute arbitrary SQL queries, write a WAR payload to disk, and trigger its deployment for remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine OpManager v11.5 and v11.6
Auth required
Prerequisites: Network access to the target · ManageEngine OpManager with default credentials
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC MANUAL
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/manage_engine_opmanager_rce.rb

This Metasploit module exploits a default credential vulnerability in ManageEngine OpManager, using a hidden 'IntegrationUser' account with a hardcoded password to authenticate and execute SQL queries. It then writes a WAR payload to disk and triggers its deployment, achieving remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine OpManager <= v11.6
Auth required
Prerequisites: Network access to the target · Default credentials for 'IntegrationUser' account
devstral-2 · analyzed Apr 24, 2026 Full analysis →

Scores

EPSS 0.7770
EPSS Percentile 99.0%

Details

Status published
Products (1)
zohocorp/manageengine_opmanager 11.5
Published Oct 09, 2015
Tracked Since Feb 18, 2026