CVE-2026-1367
Zoho ManageEngine ADSelfService Plus vulnerability analysis and mitigation

Overview

CVE-2026-1367 is an authenticated SQL injection vulnerability in Zohocorp ManageEngine ADSelfService Plus affecting builds 6522 and earlier. The flaw exists in the search report functionality within the Reports module, where user-supplied input is incorporated into SQL queries without adequate validation or sanitization. It was fixed on January 25, 2026, in build 6523, and publicly disclosed on February 23, 2026. The vulnerability carries a CVSS v3.1 base score of 8.3 (High) (ManageEngine Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). When an authenticated ADSelfService Plus technician performs a custom search within the Reports module, user-supplied input is passed directly into SQL queries sent to the ADSelfService Plus database without proper sanitization or parameterization. Exploitation requires low-privilege authenticated access (technician role) and can be performed remotely over the network with no user interaction. No public proof-of-concept exploit code has been identified as of the time of reporting (ManageEngine Advisory, Red Hat CVE).

Impact

Successful exploitation allows an authenticated technician to execute arbitrary SQL commands against the ADSelfService Plus database, resulting in high confidentiality impact (unauthorized access to sensitive data), high integrity impact (unauthorized modification or deletion of database records), and low availability impact (potential service disruption). Because ADSelfService Plus manages Active Directory credentials, password resets, and account unlocks, database compromise could expose sensitive identity and authentication data, potentially enabling lateral movement within an organization's Active Directory environment (ManageEngine Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the reporting date. The EPSS score is 0.002 (0.2%), indicating a low current probability of exploitation. The vulnerability is detected by Qualys (detection ID 530969) and has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible ManageEngine ADSelfService Plus instances running build 6522 or earlier using network scanning tools or Shodan.
  2. Authentication: Obtain or compromise credentials for an ADSelfService Plus technician account (low-privilege authenticated access is sufficient).
  3. Navigate to Reports module: Log in to the ADSelfService Plus web interface and navigate to the Reports module, which contains the vulnerable search report functionality.
  4. Inject malicious SQL payload: In the custom search/report input field, enter a crafted SQL injection payload (e.g., ' OR 1=1--, UNION-based, or time-based blind injection) that is passed unsanitized into the backend SQL query.
  5. Extract or manipulate data: Use the injected SQL to enumerate database tables, extract sensitive data (user credentials, configuration, AD account information), or modify/delete database records.
  6. Escalate or pivot: Leverage extracted credentials or configuration data to escalate privileges within ADSelfService Plus or pivot to connected Active Directory infrastructure (ManageEngine Advisory).

Indicators of compromise

  • Logs: ADSelfService Plus application logs showing unusual or malformed SQL-like strings in search/report query parameters; database error messages or stack traces triggered by malformed queries in server logs.
  • Network: Unexpected or anomalous HTTP POST/GET requests to the Reports module endpoints from unusual source IPs or at unusual times.
  • Database: Unexpected queries in database audit logs containing SQL metacharacters (', --, UNION, SELECT, OR 1=1) originating from the ADSelfService Plus application account; unusual data access patterns or bulk reads of sensitive tables.
  • Process/Application: Unexpected changes to ADSelfService Plus database records, including user account modifications, configuration changes, or new technician accounts created without administrative action.

Mitigation and workarounds

Zohocorp released a fix in ADSelfService Plus build 6523, which ensures all database queries are properly sanitized. Organizations should immediately update to build 6523 or later using the official service pack. As interim mitigations, restrict network-level access to the ADSelfService Plus interface to trusted IP ranges, apply the principle of least privilege to technician accounts, deploy Web Application Firewall (WAF) rules to detect SQL injection patterns targeting the Reports module, and monitor database access logs for suspicious query activity (ManageEngine Advisory).

Community reactions

The vulnerability was reported to Zoho through their BugBounty program by researcher Nguyen Dang Toan. A Check Point advisory (CPAI-2026-1700) was published referencing the vulnerability. Coverage has appeared on security aggregation platforms including Vulners, CVEFeed, and CIRCL, as well as a Loginsoft threat campaign summary on Medium. Community reaction has been moderate, consistent with a high-severity but authentication-required vulnerability with no known active exploitation (ManageEngine Advisory, Check Point Advisory).

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine ADSelfService Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11250CRITICAL9.1
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesJan 13, 2026
CVE-2026-11374CRITICAL9
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesJun 23, 2026
CVE-2026-2740HIGH8.4
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesMay 21, 2026
CVE-2026-1367HIGH8.3
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesFeb 23, 2026
CVE-2026-3183HIGH7.1
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management