
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-92905 is a denial-of-service (DoS) vulnerability in the log collector component of ZohoCorp ManageEngine EventLog Analyzer and Log360. Malformed syslog datagrams sent to the syslog listener port are not handled correctly, causing the collector service to crash unexpectedly. All builds prior to 13071 are affected; the vulnerability was disclosed and patched on August 25, 2026, with the advisory published September 24, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (ManageEngine Advisory, GitHub Advisory).
The root cause is an uncaught exception (CWE-248) in the syslog listener of the log collector component, where malformed syslog datagrams are not discarded safely and instead cause the service to terminate. An unauthenticated, network-adjacent attacker can send specially crafted malformed syslog packets to the syslog listener port without any credentials or user interaction required. The fix improves input validation so that malformed datagrams are silently discarded and the service continues running (ManageEngine Advisory, GitHub Advisory).
Successful exploitation causes the log collector service to crash, interrupting syslog collection until the service is restarted or the patch is applied. There is no confidentiality or integrity impact — the vulnerability is limited to availability. In environments relying on EventLog Analyzer or Log360 for security monitoring and compliance, a sustained attack could create blind spots in log visibility, potentially masking other malicious activity (ManageEngine Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.0235, indicating a low probability of exploitation in the near term. Notably, the attack is automatable and requires no authentication, meaning a low-skilled attacker could trigger the DoS with minimal effort (GitHub Advisory, ManageEngine Advisory).
netcat, scapy, or a custom script).ZohoCorp has addressed the vulnerability in build 13071, released August 25, 2026. Users should update EventLog Analyzer and Log360 to build 13071 or later using the official service pack links provided by ManageEngine. As a network-level workaround, restrict access to the syslog listener port to only trusted, known syslog sources using firewall rules or network ACLs, and monitor for anomalous syslog traffic patterns (ManageEngine Advisory).
The vulnerability was discovered by a researcher named Seth through the Zoho Bug Bounty Program and responsibly disclosed to ZohoCorp. No significant public commentary, media coverage, or notable researcher reactions beyond the vendor advisory have been observed at this time (ManageEngine Advisory).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"