← Vulnerability feed

Vulnerability record · CVE-2020-24786 · published 31 August 2020

CVE-2020-24786: Zohocorp manageengine adselfservice plus improper authentication vulnerability

Zohocorp · Manageengine Adselfservice Plus

An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus before build number 6052, O365 Manager Plus before build number 4334, Cloud Security Plus before build number 4110, ADManager Plus before build number 7055, and Log360 before build number 5166. The remotely accessible Java servlet com.manageengine.ads.fw.servlet.UpdateProductDetails is prone to an authentication bypass. System integration properties can be modified and lead to full ManageEngine suite compromise.

9.8 CVSS 3.1 Critical EPSS 13% · top 3.8% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 10.0
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
24References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus before build number 6052, O365 Manager Plus before build number 4334, Cloud Security Plus before build number 4110, ADManager Plus before build number 7055, and Log360 before build number 5166. The remotely accessible Java servlet com.manageengine.ads.fw.servlet.UpdateProductDetails is prone to an authentication bypass. System integration properties can be modified and lead to full ManageEngine suite compromise.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://medium.com/%40frycos/another-zoho-manageengine-story-7b472f1515f5
https://pitstop.manageengine.com/portal/en/community/topic/admanager-plus-fixes-and-enhancements Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/how-to-fix-the-unauthenticated-product-integration-vulnerabil Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/how-to-fix-the-unauthenticated-product-integration-vulnerabil Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/how-to-fix-the-unauthenticated-product-integration-vulnerabil Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/how-to-identify-and-mitigate-the-unauthenticated-product-inte Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/how-to-identify-and-mitigate-the-unauthenticated-product-inte Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/how-to-identify-and-mitigate-the-unauthenticated-product-inte Vendor Advisory
https://pitstop.manageengine.com/portal/en/kb/articles/manageengine-cloud-security-plus-security-advisory-regarding-unau Vendor Advisory
https://pitstop.manageengine.com/portal/en/kb/articles/manageengine-log360-security-advisory-regarding-unauthenticated-p Vendor Advisory
https://www.manageengine.com/data-security/release-notes.html Vendor Advisory
https://www.manageengine.com/products/eventlog/features-new.html Vendor Advisory
https://medium.com/%40frycos/another-zoho-manageengine-story-7b472f1515f5
https://pitstop.manageengine.com/portal/en/community/topic/admanager-plus-fixes-and-enhancements Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/how-to-fix-the-unauthenticated-product-integration-vulnerabil Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/how-to-fix-the-unauthenticated-product-integration-vulnerabil Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/how-to-fix-the-unauthenticated-product-integration-vulnerabil Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/how-to-identify-and-mitigate-the-unauthenticated-product-inte Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/how-to-identify-and-mitigate-the-unauthenticated-product-inte Vendor Advisory
https://pitstop.manageengine.com/portal/en/community/topic/how-to-identify-and-mitigate-the-unauthenticated-product-inte Vendor Advisory
https://pitstop.manageengine.com/portal/en/kb/articles/manageengine-cloud-security-plus-security-advisory-regarding-unau Vendor Advisory
https://pitstop.manageengine.com/portal/en/kb/articles/manageengine-log360-security-advisory-regarding-unauthenticated-p Vendor Advisory
https://www.manageengine.com/data-security/release-notes.html Vendor Advisory
https://www.manageengine.com/products/eventlog/features-new.html Vendor Advisory

Track CVE-2020-24786 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-40539Zoho ManageEngine ADSelfService Plus REST API auth bypass to RCEZoho ManageEngine ADSelfService Plus version 6113 and prior contains an authentication bypass in its REST API that leads to remote code execution. Be…KEVEPSS 99%analysed6.8CVE-2022-28810Zoho ManageEngine ADSelfService Plus OS command injection via custom scriptZoho ManageEngine ADSelfService Plus before build 6122 lets a remote authenticated administrator run arbitrary OS commands as SYSTEM through the poli…KEVEPSS 71%analysed10.0CVE-2019-3905Zohocorp manageengine adselfservice plus server-side request forgery (ssrf) vulnerabilityZoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.EPSS 3.3%9.8CVE-2023-48792Zohocorp manageengine adaudit plus sql injection vulnerabilityZoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.EPSS 7.0%9.8CVE-2023-48793Zohocorp manageengine adaudit plus sql injection vulnerabilityZoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.EPSS 7.0%9.8CVE-2023-35854Zohocorp manageengine adselfservice plus missing authentication for critical function vulnerabilityZoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for…EPSS 6.0%9.8CVE-2022-28219Zoho ManageEngine ADAudit Plus unauthenticated XXE leading to RCECewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XML external entity (XXE) attack that leads to remote code e…EPSS 97%analysed

Source: NIST National Vulnerability Database (record CVE-2020-24786), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.