EIP-2026-102501

PRE-CVE

ManageEngine ServiceDesk Plus 9.0 - User Enumeration

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102501. PoCs published by Muhammad Ahmed Siddiqui.

AI-analyzed exploit summary The advisory describes a user enumeration vulnerability in ManageEngine ServiceDesk Plus, where authenticated and unauthenticated users can enumerate users and domains via specific AJAX servlet endpoints. The PoC demonstrates the vulnerability by showing different responses for valid and invalid users.

Description

ManageEngine ServiceDesk Plus 9.0 - User Enumeration

Exploits (1)

exploitdb WRITEUP
by Muhammad Ahmed Siddiqui · textwebappsjsp
https://www.exploit-db.com/exploits/35891

The advisory describes a user enumeration vulnerability in ManageEngine ServiceDesk Plus, where authenticated and unauthenticated users can enumerate users and domains via specific AJAX servlet endpoints. The PoC demonstrates the vulnerability by showing different responses for valid and invalid users.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ManageEngine ServiceDesk Plus 9.0
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026