high · CVSS v3 7.5
CVE-2026-18911
ManageEngine DataSecurity Plus contains an agent authentication bypass vulnerability in versions prior to 6310. This flaw allows unenrolled
Overview
ManageEngine DataSecurity Plus contains an agent authentication bypass vulnerability in versions prior to 6310. This flaw allows unenrolled agents to send unauthorized requests to the server. It matters because unauthorized entities could interact with the application interface without proper credential validation.
Description
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.
Impact
This vulnerability impacts the integrity and availability of the DataSecurity Plus environment by permitting unauthenticated agent communications. Unauthorized actors could potentially flood or spoof agent requests, disrupting data security monitoring. Organizations utilizing vulnerable versions face an increased risk of unauthorized access within their internal network segments.
Remediation
Upgrade ManageEngine DataSecurity Plus to version 6310 or the latest available vendor-supplied patch. Restrict network access to the DataSecurity Plus agent communication ports to trusted internal subnets only. Monitor agent enrollment logs for unusual or unauthorized registration attempts.
Risk context
Rated as a high severity issue with a CVSS v3 score of 7.5, indicating a significant risk to enterprise data security infrastructure. Organizations should apply patches promptly to mitigate potential unauthorized interactions.
Affected products
- ManageEngine DataSecurity Plus < 6310
Scores
- Severity
- high
- CVSS v2
- 6.1
- CVSS v3
- 7.5
- CVSS v4
- —
- EPSS
- —