
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3183 is a broken authentication vulnerability in Zohocorp ManageEngine ADSelfService Plus that allows an attacker with knowledge of a valid user's domain password to bypass Multi-Factor Authentication (MFA) and gain unauthorized account access. It affects all builds up to and including build 6523, with build 6524 (released January 31, 2026) containing the fix. The vulnerability was publicly disclosed on July 21, 2026, and carries a CVSS v3.1 base score of 7.1 (High) (ManageEngine Advisory, GitHub Advisory).
The root cause is classified as CWE-290 (Authentication Bypass by Spoofing), stemming from incomplete enforcement of session-level authentication state checks at a sensitive API endpoint. Specifically, the application failed to verify that a session had fully completed the MFA challenge before permitting privileged operations, allowing an attacker who possesses a valid user password to interact with the endpoint and skip the MFA step entirely. Exploitation requires low privileges (a valid domain password) and is conducted over the network with no user interaction required. The fix in build 6524 enforces session-level authentication state checks at sensitive API endpoints to ensure MFA completion is mandatory before privileged actions are allowed (ManageEngine Advisory, GitHub Advisory).
An attacker who knows a valid user's domain password can fully bypass MFA protections, gain unauthorized access to that user's ADSelfService Plus account, and take over associated privileges. The primary impact is a high integrity risk — the attacker can modify sensitive data and system configurations — with a low confidentiality impact due to access to account information. Availability is not directly impacted. Given that ADSelfService Plus manages Active Directory password resets, account unlocks, and SSO, a successful bypass could enable further lateral movement within an organization's Active Directory environment (ManageEngine Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation is currently "none" and the attack is not automatable, as it requires knowledge of a specific user's domain password. The EPSS score is approximately 0.48%, placing it in the 39th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (Detection ID 531883) (GitHub Advisory).
Zohocorp has resolved this vulnerability in ADSelfService Plus build 6524, released January 31, 2026. Organizations should update their ADSelfService Plus instance to build 6524 or later using the service pack immediately. As interim measures, restrict network access to the ADSelfService Plus application using network segmentation, monitor authentication logs for anomalous bypass patterns, and consider implementing additional perimeter-level controls to independently validate MFA. No configuration-based workaround is available as a substitute for patching (ManageEngine Advisory).
The vulnerability was responsibly disclosed through Zoho's BugBounty program by security researchers Jake Zukowski and Damian Pajszczyk, and Zohocorp acknowledged and credited them in their official advisory. No significant broader media coverage or notable public researcher commentary beyond the vendor advisory has been identified at this time (ManageEngine Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."