CVE-2019-10008

HIGH

Zoho ManageEngine ServiceDesk 9.3 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2019-10008. PoCs published by Ata Hakçıl_ Melih Kaan Yıldız, ignis-sec.

AI-analyzed exploit summary This exploit demonstrates a privilege escalation vulnerability in ManageEngine ServiceDesk Plus versions below 10.0 by manipulating session cookies to bypass authentication and escalate privileges to an administrator account.

Description

Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.

Exploits (2)

exploitdb WORKING POC
by Ata Hakçıl_ Melih Kaan Yıldız · pythonwebappsjsp
https://www.exploit-db.com/exploits/46659

This exploit demonstrates a privilege escalation vulnerability in ManageEngine ServiceDesk Plus versions below 10.0 by manipulating session cookies to bypass authentication and escalate privileges to an administrator account.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine ServiceDesk Plus <10.0
Auth required
Prerequisites: Access to a low-privileged account · Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 4 stars
by ignis-sec · poc
https://github.com/ignis-sec/CVE-2019-10008

This repository contains a functional exploit for CVE-2019-10008, which allows privilege escalation in ManageEngine Service Desk Plus by manipulating session cookies. The exploit demonstrates how an attacker with low-privilege credentials can hijack a session to authenticate as a higher-privilege user without a password.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine Service Desk Plus <10.0
Auth required
Prerequisites: Valid low-privilege credentials · Access to the target application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_confirm
https://www.manageengine.com/products/service-desk/readme.html
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46659

Scores

CVSS v3 8.8
EPSS 0.1973
EPSS Percentile 97.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-384
Status published
Products (1)
zohocorp/servicedesk_plus 9.3
Published Apr 24, 2019
Tracked Since Feb 18, 2026