Support
 
Phone Live Chat
 
Support
 
US: +1 888 720 9500
US: +1 800 443 6694
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9393

 
 
 
 
 
Security Updates

[Fixed] Authenticated command injection vulnerability in custom scripts (CVE-2025-10020) - ManageEngine ADManager Plus

Vulnerability details
Severity High
CVE ID CVE-2025-10020
Affected software versions 8023 and older
Fixed version Build 8024
Fixed on September 19, 2025

Details

The CVE-2025-10020 refers to an authenticated command injection vulnerability in the Custom Script component of ADManager Plus, where improper handling could allow attackers to execute arbitrary commands, leading to remote code execution (RCE). This issue has been fixed in build 8024, and the release notes can be found here.

Impact

This vulnerability could allow an authenticated adversary to gain unauthorized access to sensitive data from the server and execute system commands to compromise the instance.

Steps to update

Update your ADManager Plus instance to its latest build by installing the service pack.

Acknowledgement

This vulnerability was reported by bitxer via Zoho's Bug Bounty program.

 

Select a language to translate the contents of this web page:

Need further assistance?

Fill this form, and we'll contact you rightaway.

Request Support

  •  
  • *
     
  • *
     
  • *
     
  • By submitting you agree to processing of personal data according to the Privacy Policy.

"Thank you for submitting your request.

Our technical support team will get in touch with you at the earliest."

ADManager Plus Trusted By

The one-stop solution to Active Directory Management and Reporting
Email Download Link email-download-top