EIP-2026-102406
PRE-CVEManageEngine ServiceDesk Plus 9.0 - Authentication Bypass
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102406. PoCs published by ByteM3.
AI-analyzed exploit summary This is a detailed technical writeup describing an authentication bypass vulnerability in ManageEngine ServiceDesk Plus 9.0, where a valid username can be used as both the username and password to compromise the application when Active Directory/LDAP is enabled. The exploit involves logging into the mobile client directory and manipulating the URL to gain full application access.
Description
ManageEngine ServiceDesk Plus 9.0 - Authentication Bypass
Exploits (1)
This is a detailed technical writeup describing an authentication bypass vulnerability in ManageEngine ServiceDesk Plus 9.0, where a valid username can be used as both the username and password to compromise the application when Active Directory/LDAP is enabled. The exploit involves logging into the mobile client directory and manipulating the URL to gain full application access.