{"id":"CVE-2025-11248","title":"ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue","summary":"ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.","severity":"low","cvss":3.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N","cwe":["CWE-532"],"vendor":"zohocorp","product":"manageengine_endpoint_central","affected":["manageengine_endpoint_central < 11.4.2528.05"],"patched":["manageengine_endpoint_central 11.4.2528.05"],"published":"2025-10-27","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-11248","references":[{"url":"https://www.manageengine.com/products/desktop-central/CVE-2025-11248.html","label":"0fc0942c-577d-436f-ae8e-945763c79b02"}],"tags":["nvd"],"epss":0.00517,"epssPercentile":0.42104,"ingestedAt":"2026-10-08T11:31:27.631Z","slug":"CVE-2025-11248","body":"## Overview\n\nZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.\n\n## Affected\n\n- `manageengine_endpoint_central < 11.4.2528.05`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `manageengine_endpoint_central 11.4.2528.05`","depth":"sunlit","depthScore":18,"depthScoreParts":{"impact":17.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}