CVE-2026-2740
Zoho ManageEngine ADSelfService Plus vulnerability analysis and mitigation

Overview

CVE-2026-2740 is an authenticated remote code execution (RCE) vulnerability affecting Zohocorp ManageEngine ADSelfService Plus, DataSecurity Plus, and RecoveryManager Plus, stemming from a bug in a third-party dependency used during agent installation. The vulnerability affects ADSelfService Plus versions before 6525, DataSecurity Plus before 6264, and RecoveryManager Plus before 6313. It was disclosed on May 21, 2026, with patches released between February and March 2026. It carries a CVSS v3.1 base score of 8.4 (High) (ManageEngine Advisory, Github Advisory).

Technical details

The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — Command Injection), rooted in a flaw within a third-party dependency used in the remote agent installation workflow (Github Advisory). During agent installation on a client machine, insufficient access control on the deployment service allows a user with valid local credentials to inject and execute arbitrary commands on that machine. The affected agents include the ADSelfService Plus login agent, RecoveryManager Plus backup agent, and DataSecurity Plus agent. Exploitation requires network access, low-level authenticated privileges, and high attack complexity, but no user interaction, and the scope extends beyond the vulnerable component (ManageEngine Advisory).

Impact

A successful exploit allows an authenticated user with valid local credentials on a client machine to execute arbitrary commands on that machine during the agent installation process, resulting in high confidentiality and integrity impact and low availability impact (ManageEngine Advisory). Because the scope is marked as Changed, the impact can extend beyond the directly vulnerable component to other resources within the environment, potentially enabling lateral movement across agent-managed systems. Sensitive data accessible on agent machines — including credentials, configuration files, and backup data — could be exposed or manipulated.

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Github Advisory). The EPSS score is approximately 1.39% (81st percentile), indicating a moderate estimated probability of exploitation within 30 days relative to other CVEs. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.

Exploitation steps

  1. Reconnaissance: Identify target environments running ManageEngine ADSelfService Plus (≤6524), DataSecurity Plus (≤6263), or RecoveryManager Plus (≤6312) with agent deployment workflows exposed on the network.
  2. Obtain local credentials: Acquire valid local credentials on a client machine where an agent is being or will be installed — this could be through phishing, credential reuse, or insider access.
  3. Trigger agent installation: Initiate or wait for the agent installation workflow to begin on the target client machine (e.g., ADSelfService Plus login agent, RecoveryManager Plus backup agent, or DataSecurity Plus agent).
  4. Inject malicious commands: During the agent installation process, exploit the insufficient access control on the deployment service by injecting specially crafted command sequences via the vulnerable third-party dependency, leveraging the CWE-77 command injection flaw.
  5. Achieve arbitrary code execution: The injected commands execute on the client machine under the context of the installation service, potentially enabling persistence, data exfiltration, or lateral movement to other agent-managed systems (ManageEngine Advisory).

Indicators of compromise

  • Logs: Unexpected or anomalous command execution entries in system logs (Windows Event Logs or Linux syslog) on agent machines during or shortly after agent installation events; unusual process creation events tied to the ManageEngine agent installer service.
  • Process: Unexpected child processes spawned by the ManageEngine agent installation service (e.g., cmd.exe, powershell.exe, bash, sh, curl, wget) on client machines.
  • File System: Unexpected scripts, executables, or configuration changes created in the ManageEngine agent installation directory or temp directories during installation windows.
  • Network: Unusual outbound network connections from agent machines to unknown external IPs following agent installation events.

Mitigation and workarounds

Zohocorp has released patched versions for all affected products: ADSelfService Plus build 6525 (released February 7, 2026), DataSecurity Plus build 6264 (released February 13, 2026), and RecoveryManager Plus build 6313 (released March 24, 2026). The fix hardens access control on the service used for deploying agents. Organizations should upgrade immediately using the official upgrade packs available from ManageEngine's service pack pages. As interim measures, implement network segmentation to restrict access to agent machines, enforce least-privilege principles for authenticated users, and monitor for suspicious process execution during agent installation (ManageEngine Advisory).

Community reactions

The vulnerability was reported through Zoho's BugBounty program and disclosed publicly on May 21, 2026, with limited broader industry commentary observed at the time of reporting (ManageEngine Advisory). Coverage has appeared on security aggregation sites including CVEFeed, VulnDB, and Infinitsec, reflecting routine community tracking of ManageEngine vulnerabilities given the product's history as a high-value target.

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine ADSelfService Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11250CRITICAL9.1
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesJan 13, 2026
CVE-2026-11374CRITICAL9
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesJun 23, 2026
CVE-2026-2740HIGH8.4
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesMay 21, 2026
CVE-2026-1367HIGH8.3
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesFeb 23, 2026
CVE-2026-3183HIGH7.1
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management