CVE-2026-18911

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

  • Published Sep 18, 2026
  • CVSS 7.5 high
  • 1.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-18911 at the National Vulnerability Database