← Vulnerability feed

Vulnerability record · CVE-2014-7862 · published 4 January 2018

CVE-2014-7862: ManageEngine Desktop Central DCPluginServelet missing access control allows admin creation

Zohocorp · Desktop Central

The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 fails to enforce access controls, letting a remote unauthenticated attacker create administrator accounts through the addPlugInUser action. Because the flaw yields full administrative access to the endpoint management platform, it is a severe risk to any exposed instance.

9.8 CVSS 3.0 Critical EPSS 81% · top 0.4% CWE-264 · Permissions and access controls
9.8CVSS 3.0 base score, v2 7.5
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote creation of administrator accounts on a management platform with a CVSS of 9.8 and very high EPSS makes this an urgent exposure.

What it is

The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 fails to enforce access controls, letting a remote unauthenticated attacker create administrator accounts through the addPlugInUser action. Because the flaw yields full administrative access to the endpoint management platform, it is a severe risk to any exposed instance.

Impact

An attacker gains a new administrator account on the Desktop Central server, which can be used to control managed endpoints, deploy software or scripts, and access data handled by the platform.

Attack surface

Reachable over the network via HTTP requests to the DCPluginServelet servlet; the CVSS vector shows no privileges or user interaction required, so no authentication is needed.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.81, 99.6th percentile) and public references include a Rapid7 Metasploit module and proof-of-concept advisories, indicating mature, widely available exploit code.

What to do

  • Upgrade Desktop Central and Desktop Central MSP to build 90109 or later.
  • Restrict network access to the Desktop Central web interface and servlet paths to trusted management networks only.
  • Audit existing administrator accounts and remove any unrecognized or unauthorized accounts.
  • Monitor and alert on addPlugInUser requests and unexpected account creation events.

Detection

  • Search web server and application logs for requests to DCPluginServelet with the addPlugInUser action.
  • Alert on creation of new administrator accounts, especially from unexpected source IPs or outside change windows.
  • Review Desktop Central audit logs for anomalous administrative account changes.
  • Monitor for Metasploit module traffic or known exploit signatures targeting the servlet.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/129769/Desktop-Central-Add-Administrator.html Issue TrackingThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2015/Jan/2 Issue TrackingMailing ListThird Party Advisory
http://www.securityfocus.com/archive/1/534356/100/0/threaded
http://www.securityfocus.com/bid/71849 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/99595 Issue TrackingThird Party AdvisoryVDB Entry
https://github.com/pedrib/PoC/blob/master/advisories/ManageEngine/me_dc9_admin.txt Third Party Advisory
https://www.manageengine.com/products/desktop-central/cve20147862-unauthorized-account-creation.html Third Party Advisory
https://www.rapid7.com/db/modules/auxiliary/admin/http/manage_engine_dc_create_admin ExploitThird Party Advisory
http://packetstormsecurity.com/files/129769/Desktop-Central-Add-Administrator.html Issue TrackingThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2015/Jan/2 Issue TrackingMailing ListThird Party Advisory
http://www.securityfocus.com/archive/1/534356/100/0/threaded
http://www.securityfocus.com/bid/71849 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/99595 Issue TrackingThird Party AdvisoryVDB Entry
https://github.com/pedrib/PoC/blob/master/advisories/ManageEngine/me_dc9_admin.txt Third Party Advisory
https://www.manageengine.com/products/desktop-central/cve20147862-unauthorized-account-creation.html Third Party Advisory
https://www.rapid7.com/db/modules/auxiliary/admin/http/manage_engine_dc_create_admin ExploitThird Party Advisory

Track CVE-2014-7862 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2014-7862), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.