CVE-2025-11250
Zoho ManageEngine ADSelfService Plus vulnerability analysis and mitigation

Overview

CVE-2025-11250 is a critical authentication bypass vulnerability in Zohocorp ManageEngine ADSelfService Plus caused by improper filter configurations (CWE-290: Authentication Bypass by Spoofing). It affects all builds prior to 6519, including all 6.5.x builds up to and including 6518. The vulnerability was reported internally via the Zoho BugBounty program, fixed on October 1, 2025, and publicly disclosed on January 13, 2026. It carries a CVSS v3.1 base score of 9.1 (Critical) (ManageEngine Advisory, Feedly).

Technical details

The root cause is classified as CWE-290 (Authentication Bypass by Spoofing), stemming from improper filter configurations within ADSelfService Plus that fail to correctly enforce authentication checks on certain endpoints or request paths. An unauthenticated remote attacker can exploit this over the network with low complexity and no user interaction required, effectively spoofing or bypassing the authentication layer to gain unauthorized access. Horizon3.ai has published attack research on this vulnerability, suggesting technical analysis of the bypass mechanism is publicly available (ManageEngine Advisory, Horizon3.ai).

Impact

Successful exploitation allows unauthenticated network attackers to bypass authentication controls and gain unauthorized access to the ADSelfService Plus management interface. This can result in unauthorized access to sensitive user data (including Active Directory credentials and configurations), modification of system settings or user information, and potential abuse of self-service password reset and account unlock features to compromise Active Directory accounts. The vulnerability has high impact on both confidentiality and integrity, with no availability impact (ManageEngine Advisory, Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.0017 (0.17%), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Horizon3.ai has published attack research on this CVE, which may lower the barrier for exploitation (Horizon3.ai).

Exploitation steps

  1. Reconnaissance: Identify internet-facing ManageEngine ADSelfService Plus instances running builds prior to 6519 using tools like Shodan or Censys, searching for the product's default web interface (typically on port 9251 or 443).
  2. Identify vulnerable endpoints: Review the application's URL structure to identify endpoints that are subject to improper filter configurations and may not enforce authentication correctly.
  3. Craft bypass request: Send a specially crafted HTTP request to a protected endpoint, exploiting the misconfigured authentication filter to spoof or skip the authentication check (specific request format detailed in Horizon3.ai research).
  4. Gain unauthorized access: Upon successful bypass, interact with the ADSelfService Plus management interface as an authenticated user, accessing sensitive user data, Active Directory configurations, or triggering password reset/account unlock operations for targeted accounts.
  5. Lateral movement: Leverage access to reset passwords or unlock accounts for privileged Active Directory users, enabling further lateral movement within the corporate network (ManageEngine Advisory, Horizon3.ai).

Indicators of compromise

  • Network: Unexpected unauthenticated HTTP requests to protected ADSelfService Plus endpoints (e.g., admin or API paths) from external or unusual IP addresses; anomalous outbound connections from the ADSelfService Plus server.
  • Logs: ADSelfService Plus access logs showing successful access to authenticated resources without a preceding valid login event; repeated requests to sensitive endpoints from a single IP without authentication tokens.
  • Application: Unexpected password reset or account unlock events for privileged Active Directory accounts initiated from the ADSelfService Plus interface; changes to system configuration without corresponding admin login records.
  • Process/System: Unusual administrative actions in Active Directory (e.g., password changes for high-value accounts) correlated with ADSelfService Plus activity logs but lacking legitimate user sessions.

Mitigation and workarounds

ManageEngine has released a fix in ADSelfService Plus build 6519, available since October 1, 2025. All organizations running builds 6518 or earlier (including all 6.5.x sub-builds) should immediately upgrade to build 6519 or later using the provided service pack. No configuration-based workaround is documented; upgrading is the only recommended remediation. Given the critical CVSS score of 9.1 and the network-accessible, unauthenticated nature of the vulnerability, patching should be treated as an urgent priority (ManageEngine Advisory).

Community reactions

Security news outlet The Hacker Wire covered the vulnerability, highlighting the critical authentication bypass and urging immediate patching (The Hacker Wire). SecurityOnline.info also reported on the patch, noting the 9.1 severity score (SecurityOnline). Horizon3.ai published dedicated attack research, indicating interest from the offensive security research community (Horizon3.ai). Social media activity on Mastodon and Bluesky was noted from The Hacker Wire, reflecting moderate community awareness.

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine ADSelfService Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11250CRITICAL9.1
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesJan 13, 2026
CVE-2026-11374CRITICAL9
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesJun 23, 2026
CVE-2026-2740HIGH8.4
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesMay 21, 2026
CVE-2026-1367HIGH8.3
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesFeb 23, 2026
CVE-2026-3183HIGH7.1
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management