CVE-2025-11250Authentication Bypass by Spoofing in Manageengine Adselfservice Plus

Severity
9.1CRITICALNVD
EPSS
0.1%
top 69.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13

Description

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
CVEList
Authentication Bypass2026-01-13
GHSA
GHSA-c737-phjj-7fvf: Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations2026-01-13

📋Vendor Advisories

1
Microsoft
Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 92020-12-08

🕵️Threat Intelligence

1
Wiz
CVE-2025-11250 Impact, Exploitability, and Mitigation Steps | Wiz