← Vulnerability feed

Vulnerability record · CVE-2023-26600 · published 6 March 2023

CVE-2023-26600: Zohocorp manageengine assetexplorer improper privilege management vulnerability

Zohocorp · Manageengine Assetexplorer

ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.

6.5 CVSS 3.1 Medium EPSS 6.3% · top 6.6% CWE-269 · Improper privilege management
6.5CVSS 3.1 base score
6.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-26600 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-44077Zoho ManageEngine ServiceDesk Plus unauthenticated RCEZoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus contain a missing-authentication flaw (CWE-306) in a servlet handling…KEVEPSS 93%analysed9.8CVE-2021-37415Zoho ManageEngine ServiceDesk Plus authentication bypass via REST APIZoho ManageEngine ServiceDesk Plus before build 11302 contains an authentication bypass (CWE-306) that lets a small number of REST-API URLs be reache…KEVEPSS 100%analysed6.5CVE-2019-8394Zoho ManageEngine ServiceDesk Plus unrestricted file upload via login page customizationZoho ManageEngine ServiceDesk Plus before 10.0 build 10012 permits remote attackers to upload arbitrary files through the login page customization fe…KEVEPSS 63%analysed9.8CVE-2023-23076ManageEngine SupportCenter Plus OS command injection in schedulesManageEngine SupportCenter Plus 11 contains an OS command injection flaw reached through the Executor in Action when creating new schedules. Because …EPSS 74%analysed9.8CVE-2022-36412Zohocorp manageengine supportcenter plus improper authentication vulnerabilityIn Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be exe…EPSS 5.2%9.8CVE-2021-44526Zohocorp manageengine servicedesk plus vulnerabilityZoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.EPSS 3.2%9.8CVE-2021-44675Zohocorp manageengine servicedesk plus msp improper authentication vulnerabilityZoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which…EPSS 6.5%

Source: NIST National Vulnerability Database (record CVE-2023-26600), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.