PT-2026-51487 · Manageengine · Ad360+4

·

CVE-2026-11374

·

Published

2026-06-23

·

Updated

2026-06-25

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ADSelfService Plus versions prior to 6529 RecoveryManager Plus versions prior to 6321 M365 Manager Plus versions prior to 4817 ADAudit Plus versions prior to 8703
Description In ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus (when deployed as integrated components within ManageEngine AD360), SSO tickets generated for session authentication can be predicted by an unauthenticated user. This allows an attacker to obtain a targeted user's identity and role information, leading to full account takeover and compromise of confidentiality, integrity, and availability across the affected systems.
Recommendations Update ADSelfService Plus to version 6529 or later. Update RecoveryManager Plus to version 6321 or later. Update M365 Manager Plus to version 4817 or later. Update ADAudit Plus to version 8703 or later.

Fix

Use of Insufficiently Random Values

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11374

Affected Products

Ad360
Adaudit Plus
Adselfservice Plus
O365 Manager Plus
Recovermanager Plus