
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6516 is a critical unauthenticated remote code execution (RCE) vulnerability in Zohocorp ManageEngine ADAudit Plus affecting all builds prior to version 8606. The vulnerability stems from flaws in the product's agent API, specifically involving authentication bypass and path traversal weaknesses that can be chained to achieve RCE. It was disclosed on July 23, 2026, with a fix released in build 8606 (fixed on April 17, 2026). The vulnerability carries a CVSS v3.1 base score of 10.0 (Critical) (ManageEngine Advisory, GitHub Advisory).
The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command / OS Command Injection), arising from vulnerabilities in the ADAudit Plus agent APIs that permit authentication bypass and path traversal (GitHub Advisory, ManageEngine Advisory). An unauthenticated remote attacker can exploit these weaknesses over the network with low attack complexity and no user interaction required. The attack vector is network-accessible, requires no privileges, and results in a scope change — meaning the impact extends beyond the vulnerable component itself. The vulnerability was reported by researcher Linhlt of VCB (ManageEngine Advisory).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary OS commands on the affected ADAudit Plus server, potentially achieving complete system compromise. Given that ADAudit Plus is an Active Directory auditing solution with privileged access to AD environments, exploitation could expose highly sensitive audit logs, credentials, and AD configuration data, and could facilitate lateral movement across the enterprise network. The CVSS scoring reflects high confidentiality and integrity impact with a changed scope, underscoring the risk of cross-component compromise (ManageEngine Advisory, GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability is rated automatable by NVD SSVC analysis, meaning exploitation can be scripted without manual interaction. The EPSS score is approximately 4.73% (91st percentile), indicating a relatively elevated probability of exploitation within 30 days compared to most CVEs. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available via Nessus (plugin 331343) and Qualys (detection ID 520227) (Feedly).
../, %2e%2e%2f); OS-level command execution logs showing processes spawned by the ADAudit Plus service account that are inconsistent with normal operations.cmd.exe, powershell.exe, bash, curl, wget, net.exe); unexpected network connections initiated by the ADAudit Plus process.The primary remediation is to update ManageEngine ADAudit Plus to build 8606 or later using the official service pack (ManageEngine Advisory). After updating, administrators should also upgrade Windows agents to version 7060 or later via the ADAudit Plus web console under Configuration → Agent Management → Manage → Installed Version. Mac agents should be upgraded to the latest version regardless of current version. If immediate patching is not feasible, restrict network access to the ADAudit Plus agent API endpoints to trusted internal networks only, implement network segmentation, and monitor for suspicious activity on affected systems.
The vulnerability received coverage from security news outlets including SecurityOnline.info and SystemTek shortly after disclosure (SecurityOnline, SystemTek). The Western Australian Government SOC issued an advisory on July 24, 2026, urging organizations to patch promptly (WA SOC Advisory). Horizon3.ai published attack research on the vulnerability, and threat intelligence platforms including ThreadLinqs and CTIP Pilot flagged it as a notable risk. Social media activity on platforms such as Mastodon and LinkedIn noted the critical severity and the absence of a public PoC at the time of disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."