{"id":"CVE-2021-37415","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-37415","summary":"Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.","details":"Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.","published":"2021-09-01T06:15:06.530","modified":"2026-06-17T04:00:29.513","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.99825,"percentile":0.99959,"asOf":"2026-08-28"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.manageengine.com"},{"type":"WEB","url":"https://www.manageengine.com/products/service-desk/on-premises/readme.html#11302"},{"type":"WEB","url":"https://www.manageengine.com"},{"type":"WEB","url":"https://www.manageengine.com/products/service-desk/on-premises/readme.html#11302"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-37415"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T04:00:29.513"}}