CVE-2026-18912EPSS p73.4%

CVE-2026-18912CVE-2026-18912

Description

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

Scoring

CVSS 7.7 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS1.50% probability of exploitation · percentile 73.4% · 2026-10-05T12:00:23Z
Last modified2026-09-18
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.