CVE-2026-3183 Details
Description
Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
A multi-factor authentication (MFA) bypass vulnerability has been identified in ManageEngine ADSelfService Plus versions prior to 6524. This vulnerability allows an attacker with a valid user's domain password to exploit inadequate session-level authentication checks at a sensitive API endpoint, thereby gaining unauthorized access to the user's account and associated privileges.
Users are advised to update their ADSelfService Plus instance to build 6524 or later. Instructions for updating can be found on the ManageEngine website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.manageengine.com/products/self-service-password/advisory/CVE-2026-3183.html | ManageEngine |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | ManageEngine |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | ManageEngine |