Vulnerability record · CVE-2020-11946 · published 20 April 2020
CVE-2020-11946: Zoho ManageEngine OpManager unauthenticated API key disclosure via servlet
Zohocorp · Manageengine Opmanager
Zoho ManageEngine OpManager before build 125120 exposes an API key through a servlet call that does not require authentication. Because the key is reachable without credentials, an attacker who can reach the service can obtain it and use it to access API-protected functionality. The flaw is a missing-authentication issue (CWE-306) rated high severity.
Description
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable disclosure of an API key with high EPSS and a CVSS of 7.5 warrants prompt patching.
What it is
Zoho ManageEngine OpManager before build 125120 exposes an API key through a servlet call that does not require authentication. Because the key is reachable without credentials, an attacker who can reach the service can obtain it and use it to access API-protected functionality. The flaw is a missing-authentication issue (CWE-306) rated high severity.
Impact
An attacker gains a valid API key, which can be used to invoke authenticated API operations on the OpManager instance. This can expose monitoring data and enable further actions permitted to that key.
Attack surface
The flaw is network-reachable (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any host that can reach the OpManager servlet endpoint can trigger it. No authentication is needed.
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is high at roughly 0.52 (98.9th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade OpManager to build 125120 or later per the vendor release notes.
- If immediate upgrade is not possible, restrict network access to the OpManager web/servlet interface to trusted management networks.
- Rotate any API keys that may have been exposed and review API access logs for unexpected use.
- Place the instance behind authentication-aware reverse proxy or VPN where feasible.
Detection
- Search web access logs for unauthenticated requests to servlet endpoints that return API key data.
- Monitor for API calls using keys from unexpected source IPs or at unusual times.
- Alert on access to the OpManager servlet paths from outside expected management subnets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cwe.mitre.org/data/definitions/306.html | Third Party Advisory |
| https://www.manageengine.com/network-monitoring/help/read-me-complete.html | Release NotesVendor Advisory |
| https://cwe.mitre.org/data/definitions/306.html | Third Party Advisory |
| https://www.manageengine.com/network-monitoring/help/read-me-complete.html | Release NotesVendor Advisory |
Track CVE-2020-11946 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-11946), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.