rootpwn

high · CVSS v3 7.5

CVE-2026-18911

ManageEngine DataSecurity Plus contains an agent authentication bypass vulnerability in versions prior to 6310. This flaw allows unenrolled

Overview

ManageEngine DataSecurity Plus contains an agent authentication bypass vulnerability in versions prior to 6310. This flaw allows unenrolled agents to send unauthorized requests to the server. It matters because unauthorized entities could interact with the application interface without proper credential validation.

Description

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

Impact

This vulnerability impacts the integrity and availability of the DataSecurity Plus environment by permitting unauthenticated agent communications. Unauthorized actors could potentially flood or spoof agent requests, disrupting data security monitoring. Organizations utilizing vulnerable versions face an increased risk of unauthorized access within their internal network segments.

Remediation

Upgrade ManageEngine DataSecurity Plus to version 6310 or the latest available vendor-supplied patch. Restrict network access to the DataSecurity Plus agent communication ports to trusted internal subnets only. Monitor agent enrollment logs for unusual or unauthorized registration attempts.

Risk context

Rated as a high severity issue with a CVSS v3 score of 7.5, indicating a significant risk to enterprise data security infrastructure. Organizations should apply patches promptly to mitigate potential unauthorized interactions.

Affected products

  • ManageEngine DataSecurity Plus < 6310

Scores

Severity
high
CVSS v2
6.1
CVSS v3
7.5
CVSS v4
EPSS

Authentication Bypass ManageEngine DataSecurity Plus Access Control High Severity

← All CVEs