---
id: CVE-2025-5496
title: >-
  ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14,
  11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion
  vulnerability in the agent setup component.
summary: >-
  ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14,
  11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion
  vulnerability in the agent setup component.
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-269
vendor: zohocorp
product: manageengine_endpoint_central
affected:
  - manageengine_endpoint_central < 11.4.2508.14
  - 'manageengine_endpoint_central >= 11.4.2510.01, < 11.4.2516.06'
patched:
  - manageengine_endpoint_central 11.4.2516.06
published: '2025-10-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-5496'
references:
  - url: >-
      https://www.manageengine.com/products/desktop-central/kb/arbitrary-file-deletion-allows-local-privilege-escalation.html
    label: 0fc0942c-577d-436f-ae8e-945763c79b02
tags:
  - nvd
epss: 0.00255
epssPercentile: 0.15724
ingestedAt: '2026-10-08T22:11:53.829Z'
---

## Overview

ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component.

## Affected

- `manageengine_endpoint_central < 11.4.2508.14`
- `manageengine_endpoint_central >= 11.4.2510.01, < 11.4.2516.06`

## Remediation

Upgrade past the affected range:

- `manageengine_endpoint_central 11.4.2516.06`
