CVE-2019-11361: Zohocorp ManageEngine Remote Access Plus

High severity, CVSS 8.8. EPSS: 3% chance of exploitation in the next 30 days.

Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover.

Affected products

  • Zohocorp ManageEngine Remote Access Plus: version 10.0.258 only

Published 2020-03-19. Last modified 2026-06-17.