CVE-2026-18911: Agent authenticated bypass vulnerability fixed in DataSecurity Plus

Vulnerability details
Severity High
CVE ID CVE-2026-18911
Affected software versions 6300 and earlier
Fixed version 6310
Fixed on Aug . 6, 2026

Details

An agent authentication bypass vulnerability allowed requests from configured yet unenrolled agents to be processed without validating credentials.

Impact

A remote attacker could potentially retrieve the agent's identity and configuration data, and use it to access the service account credential configured for domain or file-share auditing.

Fix

The issue is fixed by enforcing credential validation for all agent requests and rejecting blank or invalid credentials.

Steps to update

If your DataSecurity Plus installation build version is below 6310, we highly recommend upgrading to the latest version as soon as possible using the service pack.

Acknowledgements

  • This issue was reported by qquynh through the Zoho BugBounty program.

If you need any assistance with the upgradation or require additional information, please write to us at support@datasecurityplus.com.

Email Download Link