PT-2026-2435 · Manageengine · Adselfservice Plus

Published

2026-01-13

·

Updated

2026-02-28

·

CVE-2025-11250

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ManageEngine ADSelfService Plus versions prior to 6519
Description ManageEngine ADSelfService Plus versions before 6519 are susceptible to an authentication bypass due to improper filter configurations. This allows unauthorized access. The issue is expected to be rapidly exploited.
Recommendations Update ManageEngine ADSelfService Plus to version 6519 or later.

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2025-11250

Affected Products

Adselfservice Plus