ManageEngine RCE Flaw Enables SYSTEM Code Execution From Windows Login Screen
Critical RCE flaw in ManageEngine ADSelfService Plus allows unauthenticated SYSTEM-level code execution from the Windows logon screen, requiring physical access.
ManageEngine has patched a critical remote code execution vulnerability, CVE-2026-74849, in its ADSelfService Plus software. The flaw, with a CVSS score of 9.8, allows an unauthenticated attacker with physical access to a Windows device's logon screen to execute arbitrary code as the highly privileged NT AUTHORITY\SYSTEM user. The vulnerability exists in the GINA client component used for self-service password resets. Organizations are urged to update to build 7001 or later and restrict physical access to affected endpoints.
- ManageEngine ADSelfService Plus has a critical RCE vulnerability (CVE-2026-74849) with a CVSS score of 9.8.
- The flaw allows unauthenticated attackers to execute code as NT AUTHORITY\SYSTEM from the Windows logon screen.
- Exploitation requires physical access to the device's login screen.
- The vulnerability affects versions before build 7001 and is patched in the latest update.
Vulnerabilities mentionedAll →
- CVE-2026-748499.8—Unauthenticated OS Command Injection RCE in ManageEngine ADSelfService Plus GINA Clientpublished · Zohocorp (ManageEngine) ManageEngine ADSelfService Plus (GINA client)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-74849 | Unauthenticated OS Command Injection RCE in ManageEngine ADSelfService Plus GINA Client Zohocorp ManageEngine ADSelfService Plus builds before 7001 contain a remote code execution flaw, classified as OS command injection (CWE-78), in the GINA client component that provides Windows logon-screen self-service password reset and account unlock. The CVSS 3.1 score of 9.8 (network vector, low attack complexity, no privileges or user interaction required) indicates an unauthenticated remote attacker can exploit it over the network and fully compromise confidentiality, integrity, and availability of the affected machine. Organizations running older builds of ADSelfService Plus, especially those that have rolled the GINA client out to domain-joined Windows machines, are affected. There is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported to date, but ManageEngine products have historically been targeted quickly once details circulate. |
Full article486 words · extracted from gbhackers.com · click to collapse
ManageEngine has addressed a critical remote code execution vulnerability in ADSelfService Plus, which could allow an unauthenticated attacker to execute arbitrary code as NT AUTHORITY\SYSTEM from the Windows device’s logon screen.
This vulnerability, identified as CVE-2026-74849, affects ADSelfService Plus builds 7000 and earlier that utilize the product’s GINA client.
The issue lies within the GINA client, a component that enables self-service password reset and account unlock features directly on the Windows logon screen. The client provides these features through an embedded kiosk-style browser, creating an exposed pre-authentication interface on managed Windows endpoints.
ManageEngine RCE Flaw
According to ManageEngine, an attacker with access to a vulnerable Windows logon screen could exploit a security issue in the embedded browser, potentially allowing them to execute code in the NT AUTHORITY\SYSTEM context.
Because SYSTEM is the most privileged local security context in Windows, successful exploitation could fully compromise the affected device, including the ability to install malware, alter security settings, access local data, and establish persistence.
Public CVE records classify this issue as a critical vulnerability with a CVSS v3.1 score of 9.8, utilizing the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
This scoring indicates that the attack has low complexity, requires no attacker privileges or user interaction, and poses a significant risk to confidentiality, integrity, and availability. While the vendor advisory classifies the issue as “High,” the published CVE and NVD records assign it a critical severity score of 9.8.
The vulnerability affects ManageEngine ADSelfService Plus versions before build 7001, released on August 24, 2026. This update addresses the issue by correcting application error handling and strengthening the embedded browser used on the Windows logon screen.
This flaw is particularly concerning because it targets a pre-login component designed to help users recover their credentials or unlock accounts. Organizations typically deploy such tools broadly across employee endpoints, making asset discovery and patch verification crucial.
The vendor advisory explicitly notes that physical access to the device’s login screen is a prerequisite for exploitation. However, defenders should also evaluate how their GINA-client configuration, endpoint exposure, kiosk controls, remote access workflows, and network segmentation may influence practical attack paths.
- Identify endpoints running the ADSelfService Plus GINA client.
- Confirm whether the installed version of ADSelfService Plus is 7000 or earlier.
- Upgrade immediately to ADSelfService Plus build 7001 or later through ManageEngine’s service-pack process.
- Restrict untrusted physical access to Windows systems until affected endpoints are patched.
- Review endpoint telemetry for unexpected processes or command executions associated with logon-screen activity.
- Validate that the GINA-client browser is updated and that the remediated configuration is deployed consistently across managed devices.
ManageEngine acknowledges Marouane Belabbassi and Amjad E Alhejaili for reporting the vulnerability through the Zoho BugBounty program.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.