CVE Vulnerabilities

CVE-2025-5494

Improper Privilege Management

Published: Sep 25, 2025 | Modified: Oct 22, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup.

This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Manageengine_endpoint_centralZohocorp*11.4.2500.26 (excluding)
Manageengine_endpoint_centralZohocorp11.4.2508.01 (including)11.4.2508.14 (excluding)

Potential Mitigations

References