
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2740 is an authenticated remote code execution (RCE) vulnerability affecting Zohocorp ManageEngine ADSelfService Plus, DataSecurity Plus, and RecoveryManager Plus, stemming from a bug in a third-party dependency used during agent installation. The vulnerability affects ADSelfService Plus versions before 6525, DataSecurity Plus before 6264, and RecoveryManager Plus before 6313. It was disclosed on May 21, 2026, with patches released between February and March 2026. It carries a CVSS v3.1 base score of 8.4 (High) (ManageEngine Advisory, Github Advisory).
The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — Command Injection), rooted in a flaw within a third-party dependency used in the remote agent installation workflow (Github Advisory). During agent installation on a client machine, insufficient access control on the deployment service allows a user with valid local credentials to inject and execute arbitrary commands on that machine. The affected agents include the ADSelfService Plus login agent, RecoveryManager Plus backup agent, and DataSecurity Plus agent. Exploitation requires network access, low-level authenticated privileges, and high attack complexity, but no user interaction, and the scope extends beyond the vulnerable component (ManageEngine Advisory).
A successful exploit allows an authenticated user with valid local credentials on a client machine to execute arbitrary commands on that machine during the agent installation process, resulting in high confidentiality and integrity impact and low availability impact (ManageEngine Advisory). Because the scope is marked as Changed, the impact can extend beyond the directly vulnerable component to other resources within the environment, potentially enabling lateral movement across agent-managed systems. Sensitive data accessible on agent machines — including credentials, configuration files, and backup data — could be exposed or manipulated.
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Github Advisory). The EPSS score is approximately 1.39% (81st percentile), indicating a moderate estimated probability of exploitation within 30 days relative to other CVEs. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.
cmd.exe, powershell.exe, bash, sh, curl, wget) on client machines.Zohocorp has released patched versions for all affected products: ADSelfService Plus build 6525 (released February 7, 2026), DataSecurity Plus build 6264 (released February 13, 2026), and RecoveryManager Plus build 6313 (released March 24, 2026). The fix hardens access control on the service used for deploying agents. Organizations should upgrade immediately using the official upgrade packs available from ManageEngine's service pack pages. As interim measures, implement network segmentation to restrict access to agent machines, enforce least-privilege principles for authenticated users, and monitor for suspicious process execution during agent installation (ManageEngine Advisory).
The vulnerability was reported through Zoho's BugBounty program and disclosed publicly on May 21, 2026, with limited broader industry commentary observed at the time of reporting (ManageEngine Advisory). Coverage has appeared on security aggregation sites including CVEFeed, VulnDB, and Infinitsec, reflecting routine community tracking of ManageEngine vulnerabilities given the product's history as a high-value target.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."