CVE-2024-38869: Zohocorp ManageEngine ServiceDesk Plus

Medium severity, CVSS 5.4. EPSS: 1.1% chance of exploitation in the next 30 days.

Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25.

Affected products

  • Zohocorp ManageEngine ServiceDesk Plus: up to and including 14.7; version 14.8 only
  • Zohocorp ManageEngine ServiceDesk Plus Msp: up to and including 14.7; version 14.8 only
  • Zohocorp ManageEngine SupportCenter Plus: up to and including 14.7; version 14.8 only

Published 2024-08-23. Last modified 2026-06-17.