CVE-2023-26600: Zohocorp ManageEngine Assetexplorer

Medium severity, CVSS 6.5. EPSS: 6.3% chance of exploitation in the next 30 days.

ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.

Affected products

  • Zohocorp ManageEngine Assetexplorer: before 6.9 (fixed in 6.9); version 6.9 only
  • Zohocorp ManageEngine ServiceDesk Plus: before 14.1 (fixed in 14.1); version 14.1 only
  • Zohocorp ManageEngine ServiceDesk Plus Msp: before 13.0 (fixed in 13.0); version 13.0 only
  • Zohocorp ManageEngine SupportCenter Plus: before 11.0 (fixed in 11.0); version 11.0 only

Published 2023-03-06. Last modified 2026-06-17.