
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1367 is an authenticated SQL injection vulnerability in Zohocorp ManageEngine ADSelfService Plus affecting builds 6522 and earlier. The flaw exists in the search report functionality within the Reports module, where user-supplied input is incorporated into SQL queries without adequate validation or sanitization. It was fixed on January 25, 2026, in build 6523, and publicly disclosed on February 23, 2026. The vulnerability carries a CVSS v3.1 base score of 8.3 (High) (ManageEngine Advisory, Red Hat CVE).
The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). When an authenticated ADSelfService Plus technician performs a custom search within the Reports module, user-supplied input is passed directly into SQL queries sent to the ADSelfService Plus database without proper sanitization or parameterization. Exploitation requires low-privilege authenticated access (technician role) and can be performed remotely over the network with no user interaction. No public proof-of-concept exploit code has been identified as of the time of reporting (ManageEngine Advisory, Red Hat CVE).
Successful exploitation allows an authenticated technician to execute arbitrary SQL commands against the ADSelfService Plus database, resulting in high confidentiality impact (unauthorized access to sensitive data), high integrity impact (unauthorized modification or deletion of database records), and low availability impact (potential service disruption). Because ADSelfService Plus manages Active Directory credentials, password resets, and account unlocks, database compromise could expose sensitive identity and authentication data, potentially enabling lateral movement within an organization's Active Directory environment (ManageEngine Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the reporting date. The EPSS score is 0.002 (0.2%), indicating a low current probability of exploitation. The vulnerability is detected by Qualys (detection ID 530969) and has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat CVE).
' OR 1=1--, UNION-based, or time-based blind injection) that is passed unsanitized into the backend SQL query.', --, UNION, SELECT, OR 1=1) originating from the ADSelfService Plus application account; unusual data access patterns or bulk reads of sensitive tables.Zohocorp released a fix in ADSelfService Plus build 6523, which ensures all database queries are properly sanitized. Organizations should immediately update to build 6523 or later using the official service pack. As interim mitigations, restrict network-level access to the ADSelfService Plus interface to trusted IP ranges, apply the principle of least privilege to technician accounts, deploy Web Application Firewall (WAF) rules to detect SQL injection patterns targeting the Reports module, and monitor database access logs for suspicious query activity (ManageEngine Advisory).
The vulnerability was reported to Zoho through their BugBounty program by researcher Nguyen Dang Toan. A Check Point advisory (CPAI-2026-1700) was published referencing the vulnerability. Coverage has appeared on security aggregation platforms including Vulners, CVEFeed, and CIRCL, as well as a Loginsoft threat campaign summary on Medium. Community reaction has been moderate, consistent with a high-severity but authentication-required vulnerability with no known active exploitation (ManageEngine Advisory, Check Point Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."