CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-92905

CVE-2026-92905: Denial of Service in Zoho ManageEngine EventLog Analyzer and Log360 Log Collector

Alon Barad
Alon Barad
Software Engineer

Sep 29, 2026·5 min read·4 visits

Executive Summary (TL;DR)

Unauthenticated remote attackers can crash the ManageEngine log collector service by sending crafted, malformed syslog datagrams to the syslog listener port.

ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a denial-of-service (DoS) vulnerability that allowed unauthenticated remote attackers to crash the log collector service using malformed syslog packets.

Vulnerability Overview

Zoho ManageEngine EventLog Analyzer and Log360 contain a denial-of-service vulnerability in their log collector components. This component functions as a centralized syslog server that processes network logs from various enterprise assets. It listens on standard UDP and TCP ports to receive logging information in real time.

The vulnerability is exposed to the local or external network depending on how the syslog daemon is configured. Any unauthenticated network client capable of routing traffic to the syslog port can reach this parser. This wide attack surface makes the service highly susceptible to disruptions from internal or external sources.

Because the service handles raw, unstructured network input, robust validation at the packet boundary is required. The lack of proper exception handling within this boundary allows an attacker to terminate the daemon process entirely. This disrupts log aggregation capabilities across the enterprise.

Root Cause Analysis

The vulnerability stems from a failure to handle parsing exceptions within the syslog receiver thread pool. When a syslog packet arrives on UDP or TCP port 514, the log collector allocates a thread to process the payload. This thread attempts to parse the payload according to standard specifications like RFC 3164 or RFC 5424.

During parsing, the engine tokenizes fields such as the priority value, timestamp, hostname, and message body. If the incoming payload is malformed—such as containing non-ASCII characters in header fields, negative length values, or truncated frames—the parser generates a runtime exception. In Java, this typically manifests as an IndexOutOfBoundsException or NullPointerException during string tokenization.

Because there is no try-catch block wrapping this parsing logic, the runtime exception propagates up the call stack. The uncaught exception terminates the worker thread and, in this specific architecture, bubbles up to the main application context. The JVM then terminates the log collector service, resulting in a complete denial of service.

Code-Level Mechanics

To understand the vulnerability, consider the structure of the packet ingestion loop before build 13071. The application reads datagrams from the network socket and passes the raw bytes directly to the parser class without boundary checks. The following pseudo-code illustrates this unsafe architecture:

// Vulnerable Code Pattern
public void processPacket(byte[] data) {
    // No validation of packet structure before parsing
    SyslogParser parser = new SyslogParser();
    SyslogMessage msg = parser.parseRawBytes(data);
    // If parseRawBytes throws a RuntimeException, the thread terminates
    this.dbWriter.write(msg);
}

In the patched version (Build 13071), Zoho Corp implemented robust error boundaries around the parsing operations. The execution flow is wrapped in a try-catch block that specifically handles all runtime exceptions. This prevents the exception from propagating to the parent process and ensures the thread pool remains active:

// Patched Code Pattern in Build 13071
public void processPacket(byte[] data) {
    try {
        if (data == null || data.length < MIN_SYSLOG_LEN) {
            return; // Quick discard of trivial payloads
        }
        SyslogParser parser = new SyslogParser();
        SyslogMessage msg = parser.parseRawBytes(data);
        this.dbWriter.write(msg);
    } catch (RuntimeException e) {
        // Exception is caught locally, preventing service termination
        Logger.error("Failed to parse syslog packet: " + e.getMessage());
    }
}

This structural change isolates the parsing logic of individual packets. A malformed datagram will now only trigger a logged warning and a silent discard of the corrupted input. The main service process continues executing, maintaining availability for all other legitimate log sources.

Exploitation Methodology

Exploitation of CVE-2026-92905 does not require authentication or complex session establishment. An attacker with network access to the syslog listener port can deliver a single malformed packet to trigger the crash. The attack is entirely self-contained within the initial datagram, requiring no multi-stage interaction.

The exploit payload is structured to violate the formatting rules expected by the parser. For example, sending a sequence of control characters or an invalid facility/severity header sequence triggers the exception. Since the listener is often run over UDP, the attacker can spoof the source IP address, complicating attribution and defensive filtering.

The following diagram illustrates the sequence of events during a successful denial-of-service attack:

Once the service enters the crashed state, it ceases to listen on the designated ports. Syslog packets transmitted by other network infrastructure components are dropped. The denial of service persists until an administrator manually restarts the service or the system executes an automated recovery policy.

Technical Mitigation and Remediation

The primary remediation for CVE-2026-92905 is updating the affected products to Build 13071 or later. Zoho Corp has released consolidated service packs that apply the necessary code modifications to the log collector. Administrators should download these packs from official vendor repositories and schedule an immediate update window.

When patching is delayed, organizations must implement compensating controls at the network layer. Firewalls must restrict access to the syslog listener ports (UDP and TCP 514) to a strict whitelist of known logging sources. This prevents unauthorized network actors from interacting with the vulnerable parsing engine.

Additionally, service recovery options within the operating system should be configured to automatically restart the service. While this does not prevent the exploitation attempt, it reduces the duration of the resulting outage. Administrators can configure Windows Service Manager to restart the service immediately after a failure is detected.

Technical Appendix

CVSS Score
5.3/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Systems

Zoho ManageEngine EventLog AnalyzerZoho ManageEngine Log360

Affected Versions Detail

Product
Affected Versions
Fixed Version
ManageEngine EventLog Analyzer
Zoho Corp
< Build 13071Build 13071
ManageEngine Log360
Zoho Corp
< Build 13071Build 13071
AttributeDetail
CWE IDCWE-248 (Uncaught Exception)
Attack VectorNetwork
CVSS v3.1 Score5.3 (Medium)
ImpactDenial of Service (Availability)
Exploit StatusNo public PoC
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1499.004Endpoint Denial of Service: Application Exhaustion
Impact
CWE-248
Uncaught Exception

References & Sources

  • [1]https://www.manageengine.com/log-management/advisory/CVE-2026-92905.html
  • [2]https://nvd.nist.gov/vuln/detail/CVE-2026-92905

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•26 minutes ago•CVE-2026-88773
10.0

CVE-2026-88773: Critical HTTP Request Smuggling in Citrix NetScaler ADC and Gateway

A critical HTTP request/response smuggling vulnerability (CWE-444) exists in Citrix NetScaler ADC and Citrix NetScaler Gateway. This flaw arises from inconsistent request boundary parsing between NetScaler appliances and backend web servers, allowing remote, unauthenticated attackers to bypass security boundaries, access restricted resources, or hijack active user sessions on multiplexed TCP connections.

Amit Schendel
Amit Schendel
3 views•6 min read
•about 1 hour ago•CVE-2026-88058
8.6

CVE-2026-88058: Cross-Site Scripting via Server-Side Serialization Discrepancy in @angular/platform-server

A high-severity Cross-Site Scripting (XSS) vulnerability in Angular server-side rendering (SSR) component allows unauthenticated attackers to execute arbitrary client-side JavaScript. The flaw is caused by a parsing discrepancy between the server-side DOM emulator, Domino, and standard client-side browser HTML5 parsers. When serializing ProcessingInstruction nodes inside raw-content fallback elements, Domino fails to escape matching ancestor closing tags, causing the client-side parser to transition out of raw-text mode prematurely and execute subsequent sibling elements as active HTML.

Alon Barad
Alon Barad
4 views•9 min read
•about 2 hours ago•CVE-2026-101910
6.9

CVE-2026-101910: Server-Side Request Forgery Bypass via NAT64 Local-Use Address Range in ip-address Library

A validation bypass vulnerability exists in the npm package `ip-address` from version 10.2.0 to 10.5.1. The library's `Address6.isPrivate()` classifier fails to recognize the NAT64 local-use prefix range 64:ff9b:1::/48 as a restricted, private subnet. In networks implementing NAT64 routing configurations, an attacker can exploit this flaw to execute Server-Side Request Forgery (SSRF) and bypass local trust-boundary validations.

Alon Barad
Alon Barad
4 views•6 min read
•about 3 hours ago•CVE-2026-101913
6.3

CVE-2026-101913: Link-Local Address Validation Bypass in ip-address Library Enables SSRF

A validation bypass exists in the ip-address library prior to version 10.5.1. The Address6.isLinkLocal() method inaccurately restricted link-local classifications to the fe80::/64 subnet, failing to cover the complete RFC 4291 fe80::/10 allocation. This allows attackers to bypass SSRF filters relying on this library to safeguard local network boundaries.

Alon Barad
Alon Barad
4 views•6 min read
•about 4 hours ago•CVE-2026-84394
7.5

CVE-2026-84394: Host Confusion and SSRF Bypass via Parser Discrepancy in fast-uri

An interpretation conflict in the fast-uri library allows unauthenticated remote attackers to bypass Server-Side Request Forgery filters due to inconsistent handling of malformed bracket notation in hostnames.

Alon Barad
Alon Barad
5 views•6 min read
•about 5 hours ago•CVE-2026-84292
7.5

CVE-2026-84292: Authority Injection in fast-uri via Unvalidated Port Component

An authority injection vulnerability exists in the serialization components of fast-uri (versions before 2.4.6, 3.1.7, and 4.1.4) where unvalidated port components can contain authority delimiters (such as '@'). This results in host demotion to userinfo, redirection of traffic to an arbitrary attacker-controlled host, and downstream Server-Side Request Forgery (SSRF) without causing parser errors in standard clients.

Amit Schendel
Amit Schendel
6 views•7 min read