Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.1

CVE-2026-3183: ManageEngine ADSelfService Plus MFA Bypass

CVE-2026-3183 CVE-2026-3183
Summary

ManageEngine ADSelfService Plus, a self-service password reset tool, is vulnerable to a bypass of its multi-factor authentication feature. This means an attacker could potentially gain unauthorized access to user accounts. Users and administrators should update to version 6524 or later to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
zohocorp manageengine adselfservice plus < 6524
Original title
Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
Original description
Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
mitre CVSS3.1 7.1
Vulnerability type
CWE-290
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026