Vulnerability record · CVE-2015-7765 · published 9 October 2015
CVE-2015-7765: ManageEngine OpManager hardcoded IntegrationUser password grants admin access
Zohocorp · Manageengine Opmanager
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier ships a hardcoded password of "plugin" for the IntegrationUser account. Anyone who knows that password can authenticate and escalate to administrator access. Because the credential is static and documented in public exploit material, the flaw undermines the product's authentication model entirely.
Description
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.
AV:N/AC:L/Au:S/C:C/I:C/A:C
Automated analysis
high priorityHardcoded credentials give a direct path to administrator access, public exploit code exists, and the EPSS score is very high, though exploitation requires prior authenticated access.
What it is
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier ships a hardcoded password of "plugin" for the IntegrationUser account. Anyone who knows that password can authenticate and escalate to administrator access. Because the credential is static and documented in public exploit material, the flaw undermines the product's authentication model entirely.
Impact
An attacker with the known password gains full administrator access to OpManager, giving complete control over confidentiality, integrity and availability of the managed environment.
Attack surface
Reachable over the network via the OpManager web interface; the attacker must already hold some authenticated access to leverage the IntegrationUser credential, and no user interaction is required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.67284 (99.3rd percentile) and multiple references are tagged Exploit, including Packet Storm, Rapid7 and Exploit-DB entries, indicating public exploit code exists.
What to do
- Upgrade OpManager past 11.5 build 11600 to a release that removes the hardcoded IntegrationUser password.
- If upgrade is not immediately possible, disable or rename the IntegrationUser account and block its use.
- Restrict network access to the OpManager web interface to trusted management networks only.
- Rotate any credentials or integrations that may have relied on the IntegrationUser account.
- Audit logs for successful logins as IntegrationUser and for subsequent administrative actions.
Detection
- Search OpManager authentication logs for successful logins to the IntegrationUser account.
- Alert on administrative actions performed shortly after an IntegrationUser session begins.
- Monitor network traffic for access to OpManager management endpoints from unexpected source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-7765 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-7765), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.