CVE-2026-3183
Zoho ManageEngine ADSelfService Plus vulnerability analysis and mitigation

Overview

CVE-2026-3183 is a broken authentication vulnerability in Zohocorp ManageEngine ADSelfService Plus that allows an attacker with knowledge of a valid user's domain password to bypass Multi-Factor Authentication (MFA) and gain unauthorized account access. It affects all builds up to and including build 6523, with build 6524 (released January 31, 2026) containing the fix. The vulnerability was publicly disclosed on July 21, 2026, and carries a CVSS v3.1 base score of 7.1 (High) (ManageEngine Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-290 (Authentication Bypass by Spoofing), stemming from incomplete enforcement of session-level authentication state checks at a sensitive API endpoint. Specifically, the application failed to verify that a session had fully completed the MFA challenge before permitting privileged operations, allowing an attacker who possesses a valid user password to interact with the endpoint and skip the MFA step entirely. Exploitation requires low privileges (a valid domain password) and is conducted over the network with no user interaction required. The fix in build 6524 enforces session-level authentication state checks at sensitive API endpoints to ensure MFA completion is mandatory before privileged actions are allowed (ManageEngine Advisory, GitHub Advisory).

Impact

An attacker who knows a valid user's domain password can fully bypass MFA protections, gain unauthorized access to that user's ADSelfService Plus account, and take over associated privileges. The primary impact is a high integrity risk — the attacker can modify sensitive data and system configurations — with a low confidentiality impact due to access to account information. Availability is not directly impacted. Given that ADSelfService Plus manages Active Directory password resets, account unlocks, and SSO, a successful bypass could enable further lateral movement within an organization's Active Directory environment (ManageEngine Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation is currently "none" and the attack is not automatable, as it requires knowledge of a specific user's domain password. The EPSS score is approximately 0.48%, placing it in the 39th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (Detection ID 531883) (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible ManageEngine ADSelfService Plus instances running build 6523 or earlier using network scanning tools or Shodan.
  2. Credential acquisition: Obtain a valid Active Directory user's domain password through phishing, credential stuffing, or other means — low-privilege credentials are sufficient.
  3. Initiate authentication: Begin the login flow on the ADSelfService Plus portal using the compromised credentials, successfully passing the password authentication step.
  4. Bypass MFA at the API endpoint: Interact directly with the sensitive API endpoint that lacks proper session-level MFA state enforcement, submitting requests that the server incorrectly treats as fully authenticated sessions without requiring MFA completion.
  5. Gain unauthorized account access: Achieve full access to the target user's ADSelfService Plus account, enabling password resets, account unlocks, SSO token abuse, or privilege escalation within the connected Active Directory environment (ManageEngine Advisory).

Indicators of compromise

  • Logs: ADSelfService Plus authentication logs showing successful account access or privileged operations (e.g., password resets, account unlocks) for users who did not complete an MFA challenge; API endpoint access logs showing requests to sensitive endpoints from sessions that bypassed the MFA flow.
  • Network: Unusual or repeated API requests to ADSelfService Plus sensitive endpoints from unexpected source IPs or at unusual times, particularly where the session did not follow the expected MFA authentication sequence.
  • Behavioral: Unexpected password resets or account unlock events in Active Directory for accounts that the legitimate user did not initiate; SSO sessions established without corresponding MFA completion events in audit logs.

Mitigation and workarounds

Zohocorp has resolved this vulnerability in ADSelfService Plus build 6524, released January 31, 2026. Organizations should update their ADSelfService Plus instance to build 6524 or later using the service pack immediately. As interim measures, restrict network access to the ADSelfService Plus application using network segmentation, monitor authentication logs for anomalous bypass patterns, and consider implementing additional perimeter-level controls to independently validate MFA. No configuration-based workaround is available as a substitute for patching (ManageEngine Advisory).

Community reactions

The vulnerability was responsibly disclosed through Zoho's BugBounty program by security researchers Jake Zukowski and Damian Pajszczyk, and Zohocorp acknowledged and credited them in their official advisory. No significant broader media coverage or notable public researcher commentary beyond the vendor advisory has been identified at this time (ManageEngine Advisory).

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine ADSelfService Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11250CRITICAL9.1
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesJan 13, 2026
CVE-2026-11374CRITICAL9
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesJun 23, 2026
CVE-2026-2740HIGH8.4
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesMay 21, 2026
CVE-2026-1367HIGH8.3
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesFeb 23, 2026
CVE-2026-3183HIGH7.1
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management