Vulnerability record · CVE-2021-40539 · published 7 September 2021
CVE-2021-40539: Zoho ManageEngine ADSelfService Plus REST API auth bypass to RCE
Zohocorp · Manageengine Adselfservice Plus
Zoho ManageEngine ADSelfService Plus version 6113 and prior contains an authentication bypass in its REST API that leads to remote code execution. Because the flaw is reachable over the network without credentials, it exposes the self-service password management server to full compromise. The record does not list specific fixed versions beyond '6113 and prior' or detail the vulnerable code path.
Description
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score, KEV listing, ransomware use and near-maximum EPSS probability.
What it is
Zoho ManageEngine ADSelfService Plus version 6113 and prior contains an authentication bypass in its REST API that leads to remote code execution. Because the flaw is reachable over the network without credentials, it exposes the self-service password management server to full compromise. The record does not list specific fixed versions beyond '6113 and prior' or detail the vulnerable code path.
Impact
An unauthenticated attacker can bypass authentication and execute arbitrary code on the server, gaining control of the host and any credentials or directory data it handles.
Attack surface
Reachable over the network via the REST API with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not specify which endpoint or parameter is abused.
Exploitation
Listed in CISA KEV with known ransomware campaign use and an EPSS 30-day probability of 0.9896 (99.9th percentile); public exploit code is referenced on Packet Storm. Treat as actively exploited.
What to do
- Apply the vendor patch per the ManageEngine KB on fixing the REST API authentication bypass vulnerability.
- If immediate patching is not possible, restrict network access to the ADSelfService Plus REST API to trusted hosts only.
- Place the server behind a reverse proxy or WAF and block unauthenticated access to REST API paths.
- Rotate credentials and secrets stored or processed by the server after patching, in case of prior compromise.
- Monitor vendor advisories for updated fixed versions, since the record only states '6113 and prior'.
Detection
- Review web and application logs for unauthenticated or anomalous requests to ADSelfService Plus REST API endpoints.
- Hunt for unexpected child processes spawned by the ADSelfService Plus service (e.g., cmd.exe, powershell.exe, wscript.exe).
- Monitor for outbound connections from the ADSelfService Plus host to unfamiliar external addresses.
- Alert on file writes or new executables in web-accessible directories of the product.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-40539 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/165085/ManageEngine-ADSelfService-Plus-Authentication-Bypass-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.manageengine.com | Product |
| https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-AP | PatchVendor Advisory |
| http://packetstormsecurity.com/files/165085/ManageEngine-ADSelfService-Plus-Authentication-Bypass-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.manageengine.com | Product |
| https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-AP | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40539 | US Government Resource |
Track CVE-2021-40539 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-40539), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.