CVE Vulnerabilities

CVE-2025-5494

Improper Privilege Management

Published: Sep 25, 2025 | Modified: Oct 22, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup.

This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Manageengine_endpoint_central Zohocorp * 11.4.2500.26 (excluding)
Manageengine_endpoint_central Zohocorp 11.4.2508.01 (including) 11.4.2508.14 (excluding)

Potential Mitigations

References