EIP-2026-102501
PRE-CVEManageEngine ServiceDesk Plus 9.0 - User Enumeration
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102501. PoCs published by Muhammad Ahmed Siddiqui.
AI-analyzed exploit summary The advisory describes a user enumeration vulnerability in ManageEngine ServiceDesk Plus, where authenticated and unauthenticated users can enumerate users and domains via specific AJAX servlet endpoints. The PoC demonstrates the vulnerability by showing different responses for valid and invalid users.
Description
ManageEngine ServiceDesk Plus 9.0 - User Enumeration
Exploits (1)
The advisory describes a user enumeration vulnerability in ManageEngine ServiceDesk Plus, where authenticated and unauthenticated users can enumerate users and domains via specific AJAX servlet endpoints. The PoC demonstrates the vulnerability by showing different responses for valid and invalid users.