EIP-2026-119393

PRE-CVE

ManageEngine ADManager Plus Build < 7183 - Recovery Password Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-119393. PoCs published by Metin Yunus Kandemir.

AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in ManageEngine ADManager Plus by authenticating to the application and fetching recovery passwords for domain IDs. It leverages improper access controls to retrieve sensitive password data.

Description

ManageEngine ADManager Plus Build < 7183 - Recovery Password Disclosure

Exploits (1)

exploitdb WORKING POC
by Metin Yunus Kandemir · pythonwebappswindows
https://www.exploit-db.com/exploits/51794

This exploit demonstrates an information disclosure vulnerability in ManageEngine ADManager Plus by authenticating to the application and fetching recovery passwords for domain IDs. It leverages improper access controls to retrieve sensitive password data.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine ADManager Plus Build < 7183
Auth required
Prerequisites: Valid credentials for ADManager Plus or domain user · Network access to the target application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026