CVE-2024-9097: Zohocorp ManageEngine Endpoint Central

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.

Affected products

  • Zohocorp ManageEngine Endpoint Central: from 11.3.2428.01, before 11.3.2428.26 (fixed in 11.3.2428.26)

Published 2025-02-05. Last modified 2026-06-17.