CVE-2026-11374
Zoho ManageEngine ADSelfService Plus vulnerability analysis and mitigation

Overview

CVE-2026-11374 is a predictable SSO ticket vulnerability in ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus that allows unauthenticated attackers to perform account takeover. The flaw specifically affects these products when deployed as integrated components within ManageEngine AD360. Affected versions include ADSelfService Plus build 6528 and earlier, RecoveryManager Plus build 6320 and earlier, M365 Manager Plus build 4816 and earlier, and ADAudit Plus build 8702 and earlier. The vulnerability was disclosed on June 23, 2026, with patches released between June 3–12, 2026. It carries a CVSS v3.1 base score of 9.0 (Critical), assigned by ManageEngine (ManageEngine Advisory, GitHub Advisory).

Technical details

The root cause is the use of insufficiently random and predictable values in the generation of SSO authentication tickets (CWE-287: Improper Authentication, CWE-330: Use of Insufficiently Random Values, CWE-340: Generation of Predictable Numbers or Identifiers). When a user authenticates via SSO to any of the affected ManageEngine products integrated with AD360, the session ticket generated is predictable enough that an unauthenticated network attacker can calculate or brute-force a valid ticket value. Exploitation requires no privileges and no user interaction, but does carry high attack complexity, suggesting the attacker must perform some analysis or timing-based effort to predict the ticket. The vulnerability was reported by researcher 0xmanhnv through the Zoho BugBounty program (ManageEngine Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to obtain a targeted user's identity and role information and fully take over that user's account across the affected ManageEngine products. Given that these products manage Active Directory self-service, enterprise backup/recovery, Microsoft 365 administration, and AD auditing, a compromised account could expose highly sensitive enterprise identity infrastructure, audit logs, and cloud management capabilities. The CISA SSVC assessment rates the technical impact as "total," indicating full compromise of affected components, and the changed scope metric reflects that a successful attack can impact resources beyond the directly vulnerable component (ManageEngine Advisory, GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (GitHub Advisory). CISA's SSVC assessment records exploitation status as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 1.24% (66th percentile), indicating a moderate but not elevated near-term exploitation probability. The high attack complexity rating suggests exploitation is non-trivial, requiring the attacker to predict or enumerate valid SSO ticket values rather than exploit a simple injection flaw (Feedly).

Exploitation steps

  1. Reconnaissance: Identify ManageEngine AD360-integrated deployments exposing ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, or ADAudit Plus login portals on the network, using tools like Shodan, Censys, or internal network scanning.
  2. Identify SSO endpoint: Locate the SSO authentication endpoint used by the integrated AD360 products (typically the web login portal for the target application).
  3. Analyze ticket generation: Observe or intercept SSO ticket values (e.g., via unauthenticated access to login flows or error responses) to identify patterns in ticket structure, such as sequential numbers, timestamps, or weak random seeds.
  4. Predict valid ticket: Using the identified pattern, calculate or enumerate likely valid SSO ticket values for a target user account (e.g., an administrator).
  5. Submit predicted ticket: Craft an authentication request to the target application's SSO endpoint supplying the predicted ticket value, bypassing normal credential-based authentication.
  6. Account takeover: Upon successful ticket acceptance, gain access to the target user's session, obtaining their identity, role information, and full account access within the ManageEngine product (ManageEngine Advisory).

Indicators of compromise

  • Network: Unusual or repeated unauthenticated requests to SSO authentication endpoints of ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, or ADAudit Plus; high volume of SSO ticket submission attempts from a single IP or IP range suggesting enumeration.
  • Logs: Authentication success events for privileged accounts from unexpected source IPs or at unusual times; SSO session establishment without a corresponding prior credential authentication event in application logs.
  • Application Logs: Multiple failed or unusual SSO ticket validation attempts logged in ManageEngine application logs prior to a successful login, indicating ticket prediction/brute-force activity.
  • Process/Session: Unexpected administrative actions (e.g., account modifications, audit log access, M365 configuration changes) performed shortly after an anomalous SSO login event.

Mitigation and workarounds

ManageEngine has released patched builds for all affected products: ADSelfService Plus build 6529 (released June 3, 2026), RecoveryManager Plus build 6321 (June 5, 2026), M365 Manager Plus build 4817 (June 10, 2026), and ADAudit Plus build 8703 (June 12, 2026). The fix strengthens SSO ticket generation to prevent prediction by unauthenticated attackers. Organizations should apply the latest service packs immediately via the respective product service pack pages. As interim measures, restrict network-level access to ManageEngine portals, implement IP allowlisting, monitor for anomalous authentication patterns, and consider requiring additional authentication factors where possible (ManageEngine Advisory).

Community reactions

The vulnerability received coverage from multiple security news outlets including Heise, SecurityOnline, GBHackers, CyberSecurityNews, and CyberPress, with articles highlighting the account takeover risk to enterprise identity infrastructure (Heise, SecurityOnline). The Western Australian Government's SOC issued an advisory recommending urgent patching (WA SOC Advisory). The vulnerability was also discussed on Reddit's r/blueteamsec and referenced in The Hacker News weekly recap, reflecting broad community awareness. No significant threat actor attribution or weaponized exploit reports have emerged as of the time of this report.

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine ADSelfService Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11250CRITICAL9.1
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesJan 13, 2026
CVE-2026-11374CRITICAL9
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesJun 23, 2026
CVE-2026-2740HIGH8.4
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesMay 21, 2026
CVE-2026-1367HIGH8.3
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesFeb 23, 2026
CVE-2026-3183HIGH7.1
  • Zoho ManageEngine ADSelfService Plus logoZoho ManageEngine ADSelfService Plus
  • cpe:2.3:a:zohocorp:manageengine_adselfservice_plus
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management