
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11250 is a critical authentication bypass vulnerability in Zohocorp ManageEngine ADSelfService Plus caused by improper filter configurations (CWE-290: Authentication Bypass by Spoofing). It affects all builds prior to 6519, including all 6.5.x builds up to and including 6518. The vulnerability was reported internally via the Zoho BugBounty program, fixed on October 1, 2025, and publicly disclosed on January 13, 2026. It carries a CVSS v3.1 base score of 9.1 (Critical) (ManageEngine Advisory, Feedly).
The root cause is classified as CWE-290 (Authentication Bypass by Spoofing), stemming from improper filter configurations within ADSelfService Plus that fail to correctly enforce authentication checks on certain endpoints or request paths. An unauthenticated remote attacker can exploit this over the network with low complexity and no user interaction required, effectively spoofing or bypassing the authentication layer to gain unauthorized access. Horizon3.ai has published attack research on this vulnerability, suggesting technical analysis of the bypass mechanism is publicly available (ManageEngine Advisory, Horizon3.ai).
Successful exploitation allows unauthenticated network attackers to bypass authentication controls and gain unauthorized access to the ADSelfService Plus management interface. This can result in unauthorized access to sensitive user data (including Active Directory credentials and configurations), modification of system settings or user information, and potential abuse of self-service password reset and account unlock features to compromise Active Directory accounts. The vulnerability has high impact on both confidentiality and integrity, with no availability impact (ManageEngine Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.0017 (0.17%), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Horizon3.ai has published attack research on this CVE, which may lower the barrier for exploitation (Horizon3.ai).
ManageEngine has released a fix in ADSelfService Plus build 6519, available since October 1, 2025. All organizations running builds 6518 or earlier (including all 6.5.x sub-builds) should immediately upgrade to build 6519 or later using the provided service pack. No configuration-based workaround is documented; upgrading is the only recommended remediation. Given the critical CVSS score of 9.1 and the network-accessible, unauthenticated nature of the vulnerability, patching should be treated as an urgent priority (ManageEngine Advisory).
Security news outlet The Hacker Wire covered the vulnerability, highlighting the critical authentication bypass and urging immediate patching (The Hacker Wire). SecurityOnline.info also reported on the patch, noting the 9.1 severity score (SecurityOnline). Horizon3.ai published dedicated attack research, indicating interest from the offensive security research community (Horizon3.ai). Social media activity on Mastodon and Bluesky was noted from The Hacker Wire, reflecting moderate community awareness.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."