Manageengine · Ad360 · CVE-2026-11374
**Name of the Vulnerable Software and Affected Versions**
ADSelfService Plus versions prior to 6529
RecoveryManager Plus versions prior to 6321
M365 Manager Plus versions prior to 4817
ADAudit Plus versions prior to 8703
**Description**
In ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus (when deployed as integrated components within ManageEngine AD360), SSO tickets generated for session authentication can be predicted by an unauthenticated user. This allows an attacker to obtain a targeted user's identity and role information, leading to full account takeover and compromise of confidentiality, integrity, and availability across the affected systems.
**Recommendations**
Update ADSelfService Plus to version 6529 or later.
Update RecoveryManager Plus to version 6321 or later.
Update M365 Manager Plus to version 4817 or later.
Update ADAudit Plus to version 8703 or later.