CVE-2020-35682: Zohocorp ManageEngine ServiceDesk Plus

High severity, CVSS 8.8. EPSS: 7.2% chance of exploitation in the next 30 days.

Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).

Affected products

  • Zohocorp ManageEngine ServiceDesk Plus: before 11.1 (fixed in 11.1); version 11.1 only

Published 2021-03-13. Last modified 2026-06-17.