CVE Vulnerabilities

CVE-2025-5496

Improper Privilege Management

Published: Oct 21, 2025 | Modified: Oct 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Manageengine_endpoint_central Zohocorp * 11.4.2508.14 (excluding)
Manageengine_endpoint_central Zohocorp 11.4.2510.01 (including) 11.4.2516.06 (excluding)

Potential Mitigations

References