CVE-2025-5494

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
25/09/2025
Last modified:
22/10/2025

Description

ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup.<br /> <br /> This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zohocorp:manageengine_endpoint_central:*:*:*:*:*:*:*:* 11.4.2500.26 (excluding)
cpe:2.3:a:zohocorp:manageengine_endpoint_central:*:*:*:*:*:*:*:* 11.4.2508.01 (including) 11.4.2508.14 (excluding)