External risk intelligence

ManageEngine ADSelfService Plus GINA Client Remote Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-74849

ManageEngine ADSelfService Plus is a self-service password management and SSO solution typically deployed as a web-based service accessible to end users. Such solutions are frequently exposed to the internet or corporate edge to allow remote users to manage credentials, making the service surface likely to be reachable from outside the internal network.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in ManageEngine ADSelfService Plus, a tool used for password management and single sign-on. This issue could allow unauthorized remote code execution, potentially impacting systems that rely on this software for identity and access management. The main concern is confirming its relevance and exposure within our environment.

  • Allows remote code execution on affected systems.
  • Potential for broad impact on identity and access.
  • Confirm relevance and exposure in our environment.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by reaching the GINA client component of ManageEngine ADSelfService Plus over the network. This exposure allows for remote code execution, potentially granting the attacker significant control over the affected system.

  • Network access required.
  • Triggered via the GINA client.
  • Risk of remote code execution.

Live Threat

Current exploitation, exposure, and threat context

A critical remote code execution vulnerability exists in the GINA client of Zoho Corporation's ManageEngine ADSelfService Plus. When supported, an unauthenticated attacker could potentially execute arbitrary code on the affected system, leading to a complete compromise.

  • Affected: System data and service behavior.
  • Exposure: Via network by unauthenticated attackers.
  • Consequence: Complete system compromise is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical remote code execution vulnerability impacts Zohocorp ManageEngine ADSelfService Plus, likely managed by infrastructure or platform teams. The first action is to identify all instances, confirm their exposure and criticality, and determine the accountable owner to prioritize remediation efforts, potentially involving vendor coordination.

  • Own the issue: Infrastructure/Platform Teams.
  • Verify first: Reachability and criticality of instances.
  • Action: Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ManageEngine ADSelfService Plus?

ManageEngine ADSelfService Plus is a software solution from Zoho Corporation designed for identity and access management. Organizations use it to provide end users with self-service tools for password resets and single sign-on capabilities, often acting as a bridge between users and directory services like Active Directory.

What does this CVE-2026-74849 vulnerability mean?

This vulnerability is classified as CWE-78, which relates to OS command injection. In plain terms, it means an attacker could send specially crafted instructions to the software that the system mistakenly executes as commands. Because it allows remote code execution, it grants an unauthorized person the ability to run arbitrary operations on the server.

How is this vulnerability triggered?

The issue is triggered through the GINA client component of the software. An attacker needs network access to reach this specific component to attempt an exploit. It is important to note that actions performed outside of this GINA client pathway do not trigger this specific vulnerability.

Is my instance of ADSelfService Plus at risk?

Halo Surface Signal indicates that because this software is a web-based service frequently hosted at the corporate edge or exposed to the internet to support remote password management, it is highly likely to be reachable by external attackers. You should consider any internet-facing instance a priority for assessment.

What should I do first to address this?

Start by identifying all instances of ADSelfService Plus within your environment and confirming their current build version. Since versions before 7001 are affected, determining which systems are below this threshold is essential. Once identified, coordinate with your infrastructure teams to prioritize these systems for security updates.

References