CVE-2026-1367

HIGH

ManageEngine ADSelfService Plus <6522 - SQL Injection

Title source: llm
STIX 2.1

Description

Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.

Scores

CVSS v3 8.3
EPSS 0.0037
EPSS Percentile 58.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
Zohocorp/ManageEngine ADSelfService Plus < 6523
Published Feb 23, 2026
Tracked Since Feb 23, 2026