QSearchQSearch

CVE-2021-40539

9.8 CRITICAL

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code ex...

Published: 2021-09-07 · Last updated: 2026-06-17

Severity and scoring

CVSS
9.8 CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-706

Affected products

VendorProduct
zohocorpmanageengine_adselfservice_plus

Description

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2021-41075 The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API (9.8 CRITICAL)
  • CVE-2021-40493 Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module (9.8 CRITICAL)
  • CVE-2021-38298 Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE (9.8 CRITICAL)
  • CVE-2021-41288 Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API (9.8 CRITICAL)
  • CVE-2021-41829 Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key (7.5 HIGH)

Same CWE

  • CVE-2026-45306 pyLoad is a free and open-source download manager written in Python (6.5 MEDIUM)
  • CVE-2026-8716 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.... (4.3 MEDIUM)
  • CVE-2021-39156 Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforc... (8.1 HIGH)