PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-4107 Zohocorp CVE debrief

CVE-2026-4107 is a Stored XSS vulnerability in the Folder Message Count and Size report of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. This vulnerability could allow an attacker to inject malicious scripts into the report, potentially leading to unauthorized actions or data breaches. Users of affected versions should prioritize patching to prevent exploitation. The Common Vulnerability Scoring System (CVSS) score is 7.3, indicating a High severity level. The vulnerability affects the Folder Message Count and Size report, which could be exploited through specially crafted input.

Vendor
Zohocorp
Product
ManageEngine Exchange Reporter Plus
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Users of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 should apply patches to prevent Stored XSS attacks via the Folder Message Count and Size report. This includes administrators, security teams, and operators responsible for maintaining and securing the affected software. Prioritization is recommended due to the High CVSS score of 7.3.

Technical summary

The vulnerability, CVE-2026-4107, is a Stored XSS issue in Zohocorp ManageEngine Exchange Reporter Plus. It affects versions before 5802 and is exploitable through the Folder Message Count and Size report. The Common Vulnerability Scoring System (CVSS) score is 7.3, indicating a High severity level. The vulnerability could allow an attacker to inject malicious scripts into the report, potentially leading to unauthorized actions or data breaches.

Defensive priority

High priority for users of affected Zohocorp ManageEngine Exchange Reporter Plus versions due to the High CVSS score of 7.3 and the potential for unauthorized actions or data breaches through Stored XSS exploitation.

Recommended defensive actions

  • Apply patches to update Zohocorp ManageEngine Exchange Reporter Plus to version 5802 or later.
  • Implement compensating controls to monitor and restrict access to the Folder Message Count and Size report.
  • Conduct regular inventory checks to ensure all instances of the vulnerable software are identified and remediated.
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record for CVE-2026-4107 was published on 2026-04-03T12:16:19.067Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. However, details about the vulnerability's impact, affected configurations, and vendor statements are limited. Further verification is needed to understand the full scope of the vulnerability and potential mitigations.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T12:16:19.067Z and has not been modified since then. The NVD entry is currently Analyzed.