← Vulnerability feed

Vulnerability record · CVE-2022-40770 · published 23 November 2022

CVE-2022-40770: Zoho ManageEngine ServiceDesk Plus authenticated command injection

Zohocorp · Manageengine Servicedesk Plus

Zoho ManageEngine ServiceDesk Plus (and related MSP and SupportCenter Plus products) versions 13010 and prior contain an authenticated command injection flaw (CWE-77). A high-privileged user can inject OS commands through the application, which matters because such access can lead to full compromise of the server hosting the service desk platform.

7.2 CVSS 3.1 High EPSS 81% · top 0.4% CWE-77 · Command injection
7.2CVSS 3.1 base score
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityAuthenticated command injection with high confidentiality, integrity and availability impact and very high EPSS, though it requires high privileges and is not in KEV.

What it is

Zoho ManageEngine ServiceDesk Plus (and related MSP and SupportCenter Plus products) versions 13010 and prior contain an authenticated command injection flaw (CWE-77). A high-privileged user can inject OS commands through the application, which matters because such access can lead to full compromise of the server hosting the service desk platform.

Impact

An attacker with high privileges gains remote code execution on the underlying host, with high impact to confidentiality, integrity and availability. This effectively turns administrative application access into control of the server.

Attack surface

The flaw is reachable over the network (AV:N) with no user interaction (UI:N), but requires high privileges (PR:H), so an attacker must already hold an administrative or similarly elevated account. No public exploit detail is provided beyond the vendor advisory.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.813, ~99.6th percentile), indicating elevated predicted exploitation likelihood. All references are vendor advisories, so no public exploit code is confirmed in this record.

What to do

  • Upgrade ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus to a version later than 13010 per the vendor advisory.
  • Restrict and audit high-privileged accounts; enforce least privilege and remove unused admin roles.
  • Limit network exposure of the service desk web interface to trusted networks or VPN.
  • Monitor and alert on unexpected child processes spawned by the application server.
  • Review logs for anomalous command execution or administrative actions around the time of suspected abuse.

Detection

  • Alert on OS process creation where the parent process is the ServiceDesk Plus application or its Java/web server process.
  • Monitor for command shell or scripting interpreter launches (cmd.exe, powershell, /bin/sh) originating from the service desk service account.
  • Audit administrative account activity for unusual command or configuration changes in ServiceDesk Plus logs.
  • Correlate web requests to the service desk with subsequent suspicious process execution on the host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-40770 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-44077Zoho ManageEngine ServiceDesk Plus unauthenticated RCEZoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus contain a missing-authentication flaw (CWE-306) in a servlet handling…KEVEPSS 93%analysed9.8CVE-2021-37415Zoho ManageEngine ServiceDesk Plus authentication bypass via REST APIZoho ManageEngine ServiceDesk Plus before build 11302 contains an authentication bypass (CWE-306) that lets a small number of REST-API URLs be reache…KEVEPSS 100%analysed6.5CVE-2019-8394Zoho ManageEngine ServiceDesk Plus unrestricted file upload via login page customizationZoho ManageEngine ServiceDesk Plus before 10.0 build 10012 permits remote attackers to upload arbitrary files through the login page customization fe…KEVEPSS 63%analysed9.8CVE-2023-23076ManageEngine SupportCenter Plus OS command injection in schedulesManageEngine SupportCenter Plus 11 contains an OS command injection flaw reached through the Executor in Action when creating new schedules. Because …EPSS 74%analysed9.8CVE-2022-36412Zohocorp manageengine supportcenter plus improper authentication vulnerabilityIn Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be exe…EPSS 5.2%9.8CVE-2021-44526Zohocorp manageengine servicedesk plus vulnerabilityZoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.EPSS 3.2%9.8CVE-2021-44675Zohocorp manageengine servicedesk plus msp improper authentication vulnerabilityZoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which…EPSS 6.5%

Source: NIST National Vulnerability Database (record CVE-2022-40770), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.