
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11374 is a predictable SSO ticket vulnerability in ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus that allows unauthenticated attackers to perform account takeover. The flaw specifically affects these products when deployed as integrated components within ManageEngine AD360. Affected versions include ADSelfService Plus build 6528 and earlier, RecoveryManager Plus build 6320 and earlier, M365 Manager Plus build 4816 and earlier, and ADAudit Plus build 8702 and earlier. The vulnerability was disclosed on June 23, 2026, with patches released between June 3–12, 2026. It carries a CVSS v3.1 base score of 9.0 (Critical), assigned by ManageEngine (ManageEngine Advisory, GitHub Advisory).
The root cause is the use of insufficiently random and predictable values in the generation of SSO authentication tickets (CWE-287: Improper Authentication, CWE-330: Use of Insufficiently Random Values, CWE-340: Generation of Predictable Numbers or Identifiers). When a user authenticates via SSO to any of the affected ManageEngine products integrated with AD360, the session ticket generated is predictable enough that an unauthenticated network attacker can calculate or brute-force a valid ticket value. Exploitation requires no privileges and no user interaction, but does carry high attack complexity, suggesting the attacker must perform some analysis or timing-based effort to predict the ticket. The vulnerability was reported by researcher 0xmanhnv through the Zoho BugBounty program (ManageEngine Advisory).
Successful exploitation allows an unauthenticated attacker to obtain a targeted user's identity and role information and fully take over that user's account across the affected ManageEngine products. Given that these products manage Active Directory self-service, enterprise backup/recovery, Microsoft 365 administration, and AD auditing, a compromised account could expose highly sensitive enterprise identity infrastructure, audit logs, and cloud management capabilities. The CISA SSVC assessment rates the technical impact as "total," indicating full compromise of affected components, and the changed scope metric reflects that a successful attack can impact resources beyond the directly vulnerable component (ManageEngine Advisory, GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (GitHub Advisory). CISA's SSVC assessment records exploitation status as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 1.24% (66th percentile), indicating a moderate but not elevated near-term exploitation probability. The high attack complexity rating suggests exploitation is non-trivial, requiring the attacker to predict or enumerate valid SSO ticket values rather than exploit a simple injection flaw (Feedly).
ManageEngine has released patched builds for all affected products: ADSelfService Plus build 6529 (released June 3, 2026), RecoveryManager Plus build 6321 (June 5, 2026), M365 Manager Plus build 4817 (June 10, 2026), and ADAudit Plus build 8703 (June 12, 2026). The fix strengthens SSO ticket generation to prevent prediction by unauthenticated attackers. Organizations should apply the latest service packs immediately via the respective product service pack pages. As interim measures, restrict network-level access to ManageEngine portals, implement IP allowlisting, monitor for anomalous authentication patterns, and consider requiring additional authentication factors where possible (ManageEngine Advisory).
The vulnerability received coverage from multiple security news outlets including Heise, SecurityOnline, GBHackers, CyberSecurityNews, and CyberPress, with articles highlighting the account takeover risk to enterprise identity infrastructure (Heise, SecurityOnline). The Western Australian Government's SOC issued an advisory recommending urgent patching (WA SOC Advisory). The vulnerability was also discussed on Reddit's r/blueteamsec and referenced in The Hacker News weekly recap, reflecting broad community awareness. No significant threat actor attribution or weaponized exploit reports have emerged as of the time of this report.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."