CVE-2026-18912

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

  • Published Sep 18, 2026
  • CVSS 7.7 high
  • 1.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-18912 at the National Vulnerability Database