Remote Code Execution
Summary
| CVE | CVE-2026-2740 |
|---|---|
| State | PUBLISHED |
| Assigner | Zohocorp |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-21 14:16:44 UTC |
| Updated | 2026-05-21 15:26:35 UTC |
| Description | Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency. |
Risk And Classification
Primary CVSS: v3.1 8.4 HIGH from 0fc0942c-577d-436f-ae8e-945763c79b02
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
EPSS: 0.013940000 probability, percentile 0.806380000 (date 2026-05-27)
Problem Types: CWE-77 | CWE-77 CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 0fc0942c-577d-436f-ae8e-945763c79b02 | Secondary | 8.4 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L |
| 3.1 | CNA | CVSS | 8.4 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
LowCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Zohocorp | ManageEngine ADSelfService Plus | affected 6525 6525 | Not specified |
| CNA | Zohocorp | ManageEngine DataSecurity Plus | affected 6264 | Not specified |
| CNA | Zohocorp | ManageEngine RecoveryManager Plus | affected 6313 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.manageengine.com/products/self-service-password/advisory/CVE-2026-2740.html | 0fc0942c-577d-436f-ae8e-945763c79b02 | www.manageengine.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.