Critical ManageEngine Flaw Lets Attackers Gain SYSTEM Access Through Windows Login Screen
Critical CVE-2026-74849 in ManageEngine ADSelfService Plus lets unauthenticated attackers execute SYSTEM code via the Windows login screen.
ManageEngine has patched a critical remote code execution vulnerability (CVE-2026-74849) in ADSelfService Plus with a CVSS score of 9.8. The flaw exists in the GINA client, which presents password reset functions on the Windows login screen, and allows an unauthenticated attacker to execute arbitrary commands as the SYSTEM user. The vulnerability is caused by OS command injection (CWE-78) and was fixed in build 7001 released on August 24, 2026.
- Critical RCE vulnerability (CVE-2026-74849) in ManageEngine ADSelfService Plus.
- Allows unauthenticated attackers to execute code as SYSTEM via the Windows login screen.
- Affects builds 7000 and earlier; fixed in build 7001 released August 24, 2026.
- Root cause is OS command injection in the GINA client component.
Vulnerabilities mentionedAll →
- CVE-2026-748499.8—Unauthenticated OS Command Injection RCE in ManageEngine ADSelfService Plus GINA Clientpublished · Zohocorp (ManageEngine) ManageEngine ADSelfService Plus (GINA client)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-74849 | Unauthenticated OS Command Injection RCE in ManageEngine ADSelfService Plus GINA Client Zohocorp ManageEngine ADSelfService Plus builds before 7001 contain a remote code execution flaw, classified as OS command injection (CWE-78), in the GINA client component that provides Windows logon-screen self-service password reset and account unlock. The CVSS 3.1 score of 9.8 (network vector, low attack complexity, no privileges or user interaction required) indicates an unauthenticated remote attacker can exploit it over the network and fully compromise confidentiality, integrity, and availability of the affected machine. Organizations running older builds of ADSelfService Plus, especially those that have rolled the GINA client out to domain-joined Windows machines, are affected. There is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported to date, but ManageEngine products have historically been targeted quickly once details circulate. |
Full article526 words · extracted from cybersecuritynews.com · click to collapse
ManageEngine has fixed a critical remote code execution vulnerability in ADSelfService Plus that could allow an unauthenticated attacker to run code as NT AUTHORITY\SYSTEM through a Windows device’s login screen.
The flaw, tracked as CVE-2026-74849, affects the product’s GINA client in builds 7000 and earlier. Organizations should upgrade to build 7001 or later immediately.
The issue resides in the GINA client, a component that places ADSelfService Plus password-reset and account-unlock functions directly on the Windows logon screen.
It presents these functions in an embedded kiosk-style browser before a user signs in, allowing employees to reset passwords or unlock accounts without reaching the Windows desktop.
Critical ManageEngine Flaw
According to ManageEngine’s advisory, an attacker with access to the Windows login screen could abuse the embedded browser to execute arbitrary code in the SYSTEM security context. SYSTEM is one of the most privileged local accounts on Windows.
Code running under this context can modify protected files, create or alter user accounts, install services, turn off security tooling, access sensitive local data, and establish persistent control over the endpoint.
The vulnerability is classified as a remote code execution issue in the GINA client. Public vulnerability records identify the underlying weakness as CWE-78, Improper Neutralization of Special Elements used in an OS Command, commonly known as OS command injection.
The ManageEngine-assigned CVSS v3.1 score is 9.8 out of 10, rated Critical, with a network attack vector, low attack complexity, no privileges required, and no user interaction required.
Although the vendor advisory describes exploitation as requiring access to the Windows logon screen, defenders should treat affected systems as high risk. Login-screen software operates before normal user authentication and may run with elevated permissions.
A successful compromise could give an attacker complete control of a workstation or server hosting the vulnerable GINA component.
CVE-2026-74849 affects ManageEngine ADSelfService Plus builds 7000 and below. ManageEngine resolved the issue in build 7001, released on August 24, 2026. The update corrects the application’s error handling and hardens the embedded browser exposed at the Windows login screen.
Security teams should identify all endpoints using the ADSelfService Plus GINA client and confirm the installed product build. Any instance below build 7001 should be updated through ManageEngine’s ADSelfService Plus service pack process.
Administrators should also review endpoint logs for unexpected processes, suspicious command execution, newly created services, changes to local administrator accounts, and unusual activity originating around logon-screen use.
Where an immediate update is not possible, organizations should limit physical and remote access to affected Windows login screens, restrict exposure of the GINA-related service to untrusted networks, and closely monitor the affected hosts. These measures reduce exposure but do not replace the vendor update.
Marouane Belabbassi and Amjad E Alhejaili reported the vulnerability through the Zoho BugBounty program. With a working pathway to SYSTEM-level code execution on vulnerable systems, patching remains the most important remediation step.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.