PatchSiren cyber security CVE debrief
CVE-2026-4107 Zohocorp CVE debrief
CVE-2026-4107 is a Stored XSS vulnerability in the Folder Message Count and Size report of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802. This vulnerability could allow an attacker to inject malicious scripts into the report, potentially leading to unauthorized actions or data breaches. Users of affected versions should prioritize patching to prevent exploitation. The Common Vulnerability Scoring System (CVSS) score is 7.3, indicating a High severity level. The vulnerability affects the Folder Message Count and Size report, which could be exploited through specially crafted input.
- Vendor
- Zohocorp
- Product
- ManageEngine Exchange Reporter Plus
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Users of Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 should apply patches to prevent Stored XSS attacks via the Folder Message Count and Size report. This includes administrators, security teams, and operators responsible for maintaining and securing the affected software. Prioritization is recommended due to the High CVSS score of 7.3.
Technical summary
The vulnerability, CVE-2026-4107, is a Stored XSS issue in Zohocorp ManageEngine Exchange Reporter Plus. It affects versions before 5802 and is exploitable through the Folder Message Count and Size report. The Common Vulnerability Scoring System (CVSS) score is 7.3, indicating a High severity level. The vulnerability could allow an attacker to inject malicious scripts into the report, potentially leading to unauthorized actions or data breaches.
Defensive priority
High priority for users of affected Zohocorp ManageEngine Exchange Reporter Plus versions due to the High CVSS score of 7.3 and the potential for unauthorized actions or data breaches through Stored XSS exploitation.
Recommended defensive actions
- Apply patches to update Zohocorp ManageEngine Exchange Reporter Plus to version 5802 or later.
- Implement compensating controls to monitor and restrict access to the Folder Message Count and Size report.
- Conduct regular inventory checks to ensure all instances of the vulnerable software are identified and remediated.
- Review relevant monitoring, detection, and logs for exposed assets that need extra review.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record for CVE-2026-4107 was published on 2026-04-03T12:16:19.067Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. However, details about the vulnerability's impact, affected configurations, and vendor statements are limited. Further verification is needed to understand the full scope of the vulnerability and potential mitigations.
Official resources
-
CVE-2026-4107 CVE record
CVE.org
-
CVE-2026-4107 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
0fc0942c-577d-436f-ae8e-945763c79b02 - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T12:16:19.067Z and has not been modified since then. The NVD entry is currently Analyzed.