ZOHO Corporation has patched a critical vulnerability in the GINA client used by ManageEngine ADSelfService Plus. Tracked as CVE-2026-74849, the flaw has a CVSSv3 score of 9.8 and affects deployments using the Windows logon-screen client before build 7001. An attacker with physical or remote access to the Windows logon screen could exploit the embedded kiosk browser and execute arbitrary commands with NT AUTHORITY\SYSTEM privileges, potentially resulting in complete host compromise. Systems using only the standard web portal are not affected by this specific attack route.
According to the report, the vulnerability involves incorrect error handling in the embedded browser. By manipulating its interface, an unauthenticated attacker could bypass sandbox restrictions and cause the underlying application to run commands. The report says there is no confirmed exploitation in the wild and no public proof-of-concept code. Administrators should update ADSelfService Plus to build 7001 or later, which corrects the error handling and adds hardening for the logon-screen browser. No temporary workaround is available other than removing the GINA client from endpoints.